Skip to content

Guides & reference

Process, operations and quality engines

Syntax, computed metrics, checks and limits for value stream, CFD, queueing, SPC, Pareto, SIPOC, fault tree, bowtie, RBD, ladder, GRAFCET and more.
Sculptural study of connected forms and structured ideas

This is the syntax and behaviour reference for the Studio engines that model how work, material, risk and control logic move through a real operation. It covers lean and flow (value stream maps, cumulative flow, queueing networks, spaghetti diagrams, swimlanes, Kanban boards and service blueprints), quality and improvement (SIPOC, control charts, Pareto charts, fishbones and design structure matrices), risk, safety and reliability (fault trees, bowties, reliability block diagrams and attack trees), and automation and process engineering (ladder logic, GRAFCET and P&ID). Most of these engines do more than draw. A value stream map works out its own lead time, a control chart computes its own limits, a fault tree computes its own top-event probability, and a ladder diagram is solved for one scan. For each engine you will find the statements it reads, every keyword and alias, the defaults it assumes, what it computes, what it flags, its size limits and the templates you can start from. For a guided tour of the analysis with worked examples, read Flow-systems analysis in Studio alongside this page.

At a glance

EngineEngine idStudio library groupWhat it computes or checksReference
Value stream mapvaluestreamFlow systemsLead time, value-added time, flow efficiency, rolled throughput yield, takt, steps over takt, the constraint/docs/engines/valuestream
Flow metrics (CFD)cfdFlow systemsWIP, throughput, cycle and lead time by Little's Law, residence per stage, flow efficiency, delivery trend, runaway queues/docs/engines/cfd
Queueing networkqueueingFlow systemsTraffic equations, utilisation, waiting probability, queue length, waiting and response time, blocking, the bottleneck and the servers needed/docs/engines/queueing
Spaghetti diagramspaghettiFlow systemsTravel per actor and in total, legs, longest leg, busiest link, visits, crossings, before-and-after savings/docs/engines/spaghetti
Swimlane processswimlaneFlow & UMLColumn layout by longest path; checks decisions, exits, reachability and lanes/docs/engines/swimlane
Kanban boardkanbanFlow & UMLCard counts against WIP limits; reports lines it could not place/docs/engines/kanban
Service BlueprintserviceblueprintFlow & UMLFive-lane blueprint; reports unknown keys, repeated and empty lanes/docs/engines/serviceblueprint
SIPOCsipocFlow systemsColumn counts, requirement gaps and coverage, scope check, metric variance/docs/engines/sipoc
Control chart (SPC)spcQuality & controlCentre line and control limits, all eight Nelson rules, Cp, Cpk, Pp, Ppk and expected PPM/docs/engines/spc
Pareto chartparetoQuality & controlShares, cumulative percentage, the vital few, the Pareto ratio sentence, period-on-period movement/docs/engines/pareto
Fishbone (Ishikawa)fishboneResearch & analysisLayout of categories and causes; checks for missing problem, empty ribs and repeats/docs/engines/fishbone
Design structure matrixdsmFlow systemsCycles, partitioned order, iteration blocks, feedback marks before and after/docs/engines/dsm
Fault tree (FTA)faulttreeRisk & reliabilityExact top-event probability, rare-event approximation, minimal cut sets, single points of failure, Birnbaum, Fussell–Vesely and criticality importance/docs/engines/faulttree
Bowtie riskbowtieRisk & reliabilityResidual threat and top-event frequency, consequence risk, inherent and residual risk, risk reduction, barrier criticality/docs/engines/bowtie
Reliability block diagramrbdRisk & reliabilitySystem reliability, unreliability, MTTF, availability, Birnbaum importance, the weakest link, idle redundancy/docs/engines/rbd
Attack tree (cybersec)attacktreeRisk & reliabilityCost roll-up through AND and OR nodes; reports broken parent links/docs/engines/attacktree
Ladder logic (PLC)ladderQuality & controlOne scan solved top to bottom; duplicate destinations, outputs never energised, tags read but never written, rungs with no output/docs/engines/ladder
GRAFCET / SFCgrafcetQuality & controlAlternation, initial steps, reachability, dead ends, AND balance, receptivities, duplicate step numbers/docs/engines/grafcet
P&ID (chemical eng)pidResearch & analysisEquipment, ISA-style instrument balloons and process lines; reports unknown endpoints and overlaps/docs/engines/pid

Every engine on this page is part of the Studio's engine library and works on every plan, including Free, with no cap on how much you draw. (Free keeps three saved figures per studio; see Plans and what they include.) They all render inside flowss itself, with no outside service, so they work offline, your source never leaves flowss to be drawn, and the render API can draw them on a server. Every computation and every check on this page runs without AI. Only the optional AI features around them (Photo → Engine, AI conversion, Ask the flowss Studio Agent… edits and the flowss Studio Agent) need AI on your plan: your own key from Starter, hosted AI points from Plus. See AI points and limits.


Opening these engines

You can open any engine on this page in four ways.

  1. From the engine library. Click Engines & templates at the top of the Studio's tool rail, or click the engine name at the top of the code sheet. On the Engines tab, open the group named in the table above (Flow systems, Risk & reliability, Quality & control, Flow & UML or Research & analysis) and click the engine's row.
  2. By searching. The library's search box ("Search engines — name, or what you're drawing…") matches names and ids, what you are drawing and the tool you are replacing. Try takt, control chart, fault tree, Minitab, BowTieXP or PLC.
  3. From a link. /studio?engine=valuestream opens the Studio with that engine selected, and /studio?template=<template id> opens one template. Every engine's reference page at /docs/engines/ followed by its id has an Open in button and sample templates.
  4. From a template. Press / in the Studio to open the library on the Templates tab with its search box ready, or browse the template gallery.
Warning: Clicking an engine row replaces the current figure's source with that engine's starter template. It does not convert your diagram. ⌘Z brings the previous source back. To keep your current figure, start a New figure (⌥⌘N) first and pick the engine there. See Choosing an engine.

If you have a photograph of a whiteboard value stream map, a printed ladder diagram, a hand-drawn fault tree or a control chart taped to a machine, Photo → Engine (⋮ → Import, Plus and above) can read it into the matching engine. See Importing and converting.


What these engines have in common

Writing the source

All of these engines read plain text, one statement per line. They are forgiving by design: a half-typed line never blanks the canvas. Lines the engine cannot read are skipped and, in every engine on this page, reported rather than dropped in silence.

ConventionApplies to
# or // starts a comment anywhere on a line, outside double quotesValue stream, queueing, spaghetti, SIPOC, SPC, Pareto, fault tree, bowtie, RBD, ladder, GRAFCET
# or // starts a comment at the start of a line, or after a space later in the lineCFD (text inside double quotes is protected) and DSM (it is not, so keep # out of DSM names). This is what lets names such as C# and http://svc survive
# or // starts a comment only at the start of a lineSwimlane, Kanban, Fishbone, Attack tree, P&ID
# at the start of a line is a commentService Blueprint. A line starting // is reported as not read
Keywords are case-insensitiveAll
Quote a name that contains spaces, punctuation or a keywordAll. Double quotes work everywhere; several engines also accept single quotes
Blank lines and indentation are decorationAll except the ladder branch block, where indentation marks the legs
Tip: In the engines that only accept whole-line comments, a trailing // note after a statement becomes part of that statement. Put comments on a line of their own.

Units and numbers

The quantitative engines read units the way you would say them.

EngineDurationsA bare number meansPercentages
Value stream mapms, s, m, h, d, w and their long forms, or compound 1h30mSeconds92%, 0.92 and 92 are the same
Queueing network250ms, 30s, 8m, 2.5h, 1d, 1w, 1shift (8 hours), compound 1h30mSeconds for a duration, per hour for a rate85%, 0.85 or 85
Fault trees, min, h, d, w, mo, yHours for a duration, a probability for an event valueNot used
Reliability block diagrams, min, h, d, w, mo, y (18 months, 2.5 y)HoursNot used
BowtieNot usedThe statement's natural quantity0.8, 80% or 80
CFDDates YYYY-MM-DD or YYYY/MM/DDA cumulative countNot used

Defaults are stated, never hidden

Where an engine assumes a value you did not write, it says so on the figure. For example, a fault tree prints its mission time as "8760 h (default)" when you gave none, a bowtie lists every assumed likelihood, severity and effectiveness in its findings, and a queueing network notes when it is sizing servers against the default 85% target.

How findings are graded

Each engine's own checks report findings at one of five levels. This page uses the same five words in each engine's findings table.

LevelMeaningAffects readiness
ErrorTwo statements that cannot both be true of one document, or a line that was not read and so is in no totalYes
WarningProbably not what you meantYes
GapThe engine could not decide, for example because a size limit was reached. Never your mistake, and never silenceYes
InfoA fact worth stating that is nobody's defect, such as the study's own resultNo
OKA check that ran and found nothingNo

Every engine on this page has its checks wired into the readiness reading in the Document status popover beside the document title (click the status glyph, or press ⇧⌘M). Errors and warnings count against the figure and gaps are recorded as things that could not be checked, so a fault tree with a cyclic gate or a GRAFCET chart whose steps do not alternate cannot read as finished, however tidy it looks. See The Studio editor.

Note: A low flow efficiency, a step over takt, an out-of-control chart, a large walking distance or a single point of failure is never reported as a defect. These are the results the figure exists to show. The checks are mostly about whether the engine read your document completely and whether its statements agree with each other. A few design problems are raised on purpose: a queueing station at or above 100% utilisation has no steady state, so no queue length or waiting time exists for it, and the engine reports that as an Error rather than print numbers that are not answers; a queueing station over its target, a bowtie path with fewer than two barriers or a barrier that changes nothing, and RBD redundancy that buys almost nothing are Warnings.

When a document is too big

Swimlane, Pareto and GRAFCET read lines of up to 2,000 characters, as do Petri nets, the causal DAG and the quadrant matrix. A longer line is not read, and the figure says so by line number, for example "Line 4 was not read — it is 2,431 characters long, and this engine reads lines of up to 2,000 — split it into shorter lines".

Each engine caps the size of what it analyses, listed in Limits at a glance. When a cap is reached the engine keeps drawing what it read, says how much it did not read, and withholds any verdict that would be a claim about the whole: a value stream shows "Flow efficiency (withheld)", a fault tree shows "Top event probability (withheld)", a queueing network names no bottleneck, and sums such as lead time are shown with "≥" because they are floors. If the cut fell before anything drawable, the figure says "…is empty because the document was not read to the end" rather than showing an empty-document hint.

Where results appear

Results are part of the figure: a strip of metric tiles, a findings or notes strip, and marks on the drawing itself (a red step, a bottleneck badge, a highlighted cut set). Exports carry them, so a reviewer sees what you saw. Exports are covered in Exporting your work.


Lean and flow

Value stream map

A lean value stream map whose totals are derived from its steps, so the picture and its numbers cannot drift apart.

title "ED patient flow — current state"
supplier "Walk-ins + ambulance"
customer "Discharged patients" demand: 320/day
available 24h/day
control "Bed-board / EPR"

process Triage { ct: 6m; co: 0; uptime: 98%; operators: 2; shifts: 3 }
wait 22m
process "Doctor assessment" { ct: 18m; uptime: 92%; operators: 4; fpy: 88% }
inventory 12 patients
process Imaging { ct: 35m; uptime: 80%; operators: 3 }

info "Bed requests" from Triage to control electronic
info "Ward assignment" from control to customer manual

Statements

StatementAlso acceptedWhat it does
title "…"title: …The figure's title. The first one wins
process NAME { key: value; … }step, operation, op, activity, or just NAME { … }A value-adding step. The data box may span several lines, with ; optional between entries
wait 22mdelay, queue, lagNon-value-added time between steps
inventory 12 patientsinv, stock, buffer, wip, backlogA queue written as a count. Converted to time as count × takt when takt is known. inventory 40 orders 2h pins the time explicitly
supplier "…"vendorThe supplier box in the top band
customer "…" demand: 320/dayclientThe customer box. demand: feeds takt
control "…"production control, planning, schedulingThe production-control box
demand 320/daydemand 320 per dayCustomer demand on its own line. A number with no period is read per day
available 24h/dayavailable timeWork time per demand period. The period after / or per is documentation
takt 4.5mtakt timeDeclares takt outright, overriding the derived value
info "label" from X to Yinformation, signalAn information arrow across the top band

Information-flow endpoints are supplier, customer, control or a process name (matched without regard to case, and by prefix). The arrow is dashed when the line contains electronic, edi, digital, system or automatic, and solid otherwise (manual and paper are accepted as documentation).

Data-box keys

KeyAliasesValueMeaning
ctc/t, cycle, cycle time, cycletime, time, vat, vaDurationCycle time, the step's value-added time
coc/o, changeover, changeover time, setup, setup timeDurationChangeover. co: 0 is a real statement, not a blank
uptimeavailability, avail, oee, upPercentageShare of time the step is available
operatorsoperator, ops, people, staff, headcount, fteCountParallel operators
shiftsshiftCountShifts worked
fpyyield, first pass yield, first-pass yield, quality, ftrPercentageFirst-pass yield
batchbatch size, lot, lot sizeCountBatch size
scrapdefects, reject, reworkPercentageScrap rate

Entries may be written key: value, key = value or key value. A key the engine does not model, such as wip: 40, is still shown as an extra row in the data box rather than dropped (up to six extra keys per box).

What it computes

TileHow it is computed
Lead timeSum of all cycle times plus all waits and converted inventories
Value-added timeSum of cycle times
Flow efficiencyValue-added time ÷ lead time. Green at 20% or more, amber from 5%, red below 5%
Process stepsNumber of process boxes
Rolled throughput yieldProduct of first-pass yields; steps without fpy count as 100%. Shown only when some step declares a yield. Green at 90% or more
Takt or Takt (derived)As declared, or available time ÷ demand
Steps over taktSteps whose effective cycle time exceeds takt. Reads "none" when every step keeps up
Constraint (eff. C/T)The step with the largest effective cycle time

Effective cycle time is cycle time ÷ uptime ÷ operators. Downtime stretches the interval between finished units and parallel operators divide it, so a four-doctor room with an 18-minute consultation is not flagged against a 4.5-minute takt. Without takt (no takt line, and not both demand and available), the takt tiles are simply left out, and a count-only inventory contributes nothing to lead time; the figure shows the raw count instead.

The drawing shows the supplier and customer band with the information arrows, the process boxes with data boxes beneath (up to ten rows each), inventory triangles between steps, and the sawtooth timeline ladder along the bottom, with waits on the upper steps and value-added time on the lower ones.

What it checks

Every line that matches no statement is an Error, because this engine has no catch-all: a mistyped delya 3600 would otherwise take its wait out of the lead time, demnd 400 would leave the map with no takt, and procss "Weld" ct 90 would remove a box and its cycle time from every sum. Up to six such lines are listed one by one, then "…and N further lines." When a size limit is reached, a Gap says so, sums are shown as floors ("Lead time (partial)" with "≥") and the ratios are withheld ("Flow efficiency (withheld)", "Constraint (withheld)").

Note: The document check currently reads only lines that start with a statement keyword. A step written as a bare Triage { ct: 6m } without the process keyword, and the continuation lines of a data box spread over several lines, are drawn and counted correctly on the map but are reported as lines not read in Document status. To keep the status clean, start every step with process and keep each data box on one line.

Templates: Hospital Blood Transfusion, Vaccine Fill-Finish Suite, Adult Passport Renewal, Emergency Department, Automotive Door Line, Deployment Pipeline, Mortgage Approval, Restaurant Kitchen Line, Warehouse Fulfilment, Motor Insurance Claims, Semiconductor Fab Module, Speciality Coffee Roastery and Postgraduate Admissions.

Flow metrics (CFD)

A cumulative flow diagram with the flow metrics derived from the same numbers.

title "Platform team — Q3"
unit stories
stages: Backlog*, Ready*, In progress, Review*, Done
commit Ready
wip-limit "In progress" 8
2024-07-01 | 148, 26,  8,  4,  0
2024-07-08 | 156, 34, 18, 13,  9
2024-07-15 | 165, 44, 29, 23, 19

Statements

StatementAlso acceptedWhat it does
title "…"Title. Read only before the first data row
unit storiesunitsWhat one count is. Default items
stages: A, B, Cstage: (the colon is required)The workflow from left to right. The last stage is "done". A second stages: line is ignored and reported
commit Readycommitment, commit point, commitment pointThe commitment point. Work before it counts as backlog, not WIP. Defaults to the first stage. Only the first commit line is used
wip-limit "Stage" 8wip limit, wiplimit, wip_limit, wip-limits, limit, limits; : or = before the number also workA dashed WIP-limit line on that band, flagged when exceeded. Up to eight limits. The stage name is matched without regard to case; a limit whose name matches no stage is currently ignored without a finding, so check the spelling if no dashed line appears
A data row, such as 2024-07-01, 148, 26, 8A pipe character between the date and the counts, as in the example aboveOne cumulative count per stage

A trailing * on a stage name, or (queue), (queued), (wait), (waiting) or (q), marks it as a waiting stage. Without at least one waiting stage, flow efficiency reads "n/a" with the caption "mark queue stages with *", rather than being guessed.

Data rows hold, for each stage, how many items had entered that stage by that date. Dates may use - or /. Rows need not be evenly spaced: the x axis is a real date axis and per-day rates use the actual elapsed days. Rows out of date order are sorted. A row label that is not a date is allowed when you use the pipe (for example Sprint 1 | 40, 12, 3); the chart then works in periods rather than days. Numbers may contain _ separators.

What it computes

TileMeaning
WIPItems between the commitment point and done. Caption "committed at Ready" or "arrivals − departures"
ThroughputItems finished over the window, per week and per day (or per period when rows are not dated)
Cycle time ≈Little's Law: WIP ÷ throughput. Approximate, because Little's Law holds for averages of a stable system
Lead time ≈All items in the system, including backlog, ÷ throughput
Flow efficiencyThe share of committed WIP in active rather than waiting stages. Amber below 40%
Delivery trendDelivery rate in the second half of the window against the first, per day. "steady" within ±10%, otherwise "accelerating" or "slowing"

A table beneath the chart has one row per stage, with the columns Stage, Type ("active", "waiting" or "done"), WIP (in your unit), Limit ("—" when none is declared) and Time (in days, or periods when rows are not dated). Time is the stage's residence time, its current WIP ÷ throughput; over the committed stages these add up to the cycle time. A WIP figure over its limit is shown in bold in the warning colour.

Warnings and notes

Up to six warnings and five notes are printed under the chart.

MessageMeaning
"Queue growth: Review widened for 4 straight periods (… → …, +12 stories)"A waiting band grew for three or more consecutive periods: arrivals have outrun service. "WIP growth" is the same for an active band
"In progress holds 11 stories against a WIP limit of 8"The band's current WIP exceeds its declared limit
"Arrivals outran deliveries by 30 stories across the window"More arrived than finished
"Rows were out of date order and have been sorted"Rows were reordered
"3 values raised — a cumulative count cannot fall"A count dipped and was raised to the previous row's value
"2 values capped — a stage cannot receive more than the one before it"A downstream count overtook its upstream one
"No stages: line — assumed 4 stages ending in Done"Rows arrived without a stages: line
"Commit on the terminal stage Done would leave no WIP — measuring from Backlog"The commitment point named the last stage
"Unknown commit stage "Redy" — measuring from Backlog"The commitment point named no stage

The chart needs at least two stages and one data row; until then it shows a syntax hint headed "Cumulative flow diagram".

What it checks

FindingLevelMeaning
Value not readErrorA non-numeric token among a row's counts. The counts after it shift into the wrong stages
Line not readErrorA line that is neither a directive nor a data row
Stages undeclaredWarningRows arrived with no stages: line, so the bands were named "Stage 1", "Stage 2" and so on, ending in "Done"
Row shortWarningA row with fewer counts than stages. The missing counts are padded with zero and drawn as measurements
Directive ignoredWarningA stages:, commit or wip-limit line that was recognised but not used, such as a second stages: line
Chart truncatedGapStages, rows or counts past the limits were not read

Templates: Software Delivery Team, Support Ticket Queue, Hiring Requisition Pipeline, Manufacturing Cell WIP, Video Content Pipeline, Hospital Bed Flow, Mortgage Application Flow, ML Experiment Queue, Newsroom Editorial Pipeline, Incident Backlog Burn-down, Council Planning Applications, Clinical Trial Site Activation and Vulnerability Remediation Queue.

Queueing network

An open queueing network that is solved, not merely drawn.

title "Emergency department — Monday evening"
target 85%
arrivals Triage 12/h

station Triage     { servers: 2; service: 8m }
station Assessment { servers: 4; service: 15m }
station Imaging    { servers: 3; service: 30m; capacity: 8 }
station Discharge  { servers: 3; service: 10m; cv: 1.4 }

route Triage -> Assessment 1.0
route Assessment -> Imaging 0.35
route Assessment -> Discharge 0.65
route Imaging -> Discharge 1.0
route Discharge -> exit 1.0

This network solves as M/M/2, M/M/4, M/M/3/8 and G/G/3, and the figure's verdict reads "Bottleneck: Triage at ρ = 80% on 2 servers — already inside the 85% target; the network is balanced." The network line reads "Offered 12/h · throughput 11.9/h · blocked 0.11/h (0.9%) · L 14.96 in system · W 75.5m end to end · 4 stations", because Imaging's eight places turn a few arrivals away. Change Assessment to servers: 3 and the verdict becomes "Unstable — Assessment is offered 3 erlangs across 3 servers (ρ = 100%), so its queue grows without bound. 4 servers (1 more) would hold ρ at or under 85%."

Statements

StatementAlso acceptedWhat it does
station NAME { … }node, queue, server, resource, desk, stage, centre, center (and their plurals), or a bare NAME { … }. Braces are optional: station Triage servers: 2 service: 8mA service centre. The block may span several lines
arrivals [station] RATEarrival, external, external arrivals, demand, offered; to, at, into, for or of before the name are optionalAn outside Poisson stream. With no station named it enters the first station. Several lines add up
route A -> B 0.35The keyword is optional, and flow, link or path also work; arrows ->, -->, =>, →, ➔, ⟶A routing probability. A chain such as A -> B -> C becomes two routes. A line that starts with an arrow (continuing the line above) is reported as not read
target 85%target utilisation, target rho, target load; 85%, 0.85 or 85The utilisation the verdict sizes servers against. Default 85%
rate unit /hrate units, rates; per hour also worksDisplay unit for rates: per second, minute, hour, day, week or shift. Otherwise taken from the first arrival stream
title "…"Title. Read only before the first station

Station keys

KeyAliasesMeaning
serversserver, c, agents, channels, lines, bays, desks, staff, operators, seats, workers, executors, pumps, tills, number of serversParallel servers, at least 1 and at most 512
serviceservice time, mean service, st, ts, s, duration, handle, handling, ahtMean service time
service ratemu, μService rate instead of time, for example 7.5/h
capacityqueue capacity, k, buffer, room, limit, spaces, slotsTotal allowed in the station, in service plus waiting (at most 512). Makes it a finite-capacity station that turns arrivals away
cvservice cv, cs, cvsCoefficient of variation of service time. Default 1 (exponential)
cvaarrival cv, caCoefficient of variation of arrivals. Default 1 (Poisson)

Some keys are refused on purpose, kept as a label under the station, and reported as a coerced value so you know the number was not used:

Refused keyWhy
scv, scvs, cs2, scva, ca2A squared coefficient of variation. Write cv or cva with the unsquared value; confusing the two is a classic source of wrong answers
lambda, arrival rateAn outside arrival rate belongs on its own line: arrivals NAME 12/h
rho, utilisation, utilizationUtilisation is computed from the servers, the service time and the traffic equations, so it cannot be stated

Any other key, such as owner: or note:, is kept and shown under the station (up to six per station).

Rates are written 12/h, 0.2/s, 450/day, 42/min, 18/shift (an 8-hour shift) or 12 per hour. A bare number is per hour. Route probabilities are 0.35, 35%, p: 0.35 or @ 0.35, and default to 1. A trailing whole number other than 0 or 1 is read as part of the station name, so -> Bay 3 is a station called "Bay 3"; quote a name such as "Line 1" to keep its digit. exit, exits, out, output, sink, end, done, depart, departure, leave, leaves, external, world and none all mean "leaves the network" unless a station has that name. Any probability a station does not route away leaves the network, so -> exit lines are documentation. A station named only in a route or an arrivals line is created with one server and no service time, so a half-typed network still draws. A route or arrivals line may shorten a station's name to its start (-> Assess finds "Assessment") as long as only one station begins that way; a station declaration never matches by prefix.

Which model is used

You declareModel shownMethod
Servers and service only (no cv or cva, or both equal to 1), one serverM/M/1Exact
The same, several serversM/M/c, shown with the count (for example M/M/3)Erlang C
A capacityM/M/c/K (for example M/M/2/6)Exact birth–death chain, with blocking. Any cv or cva is ignored and reported
One server, a cv other than 1 and no cva other than 1M/G/1Pollaczek–Khinchine (exact)
Any other combination: several servers with a cv other than 1, or any cva other than 1G/G/c (for example G/G/3, or G/G/1)Allen–Cunneen approximation

The engine first solves the traffic equations for every station's arrival rate, feedback loops included, then solves each station, then the whole network. For finite-capacity stations, blocking and throughput are solved together until they agree.

What it shows

  • Each station is drawn as a waiting-line comb feeding its server circles, laid out left to right in routing order. Outside arrivals enter from the left and exits leave to the right; forward skips arc over the row and feedback loops arc under it, every arrow carrying its probability. Circles are green under 70% utilisation, amber from 70% and red from 85%. The bottleneck carries a bottleneck badge, or saturated if it is unstable. Under each station: λ and ρ; Wq and Lq; W and L; the model (for example M/M/2) with either P(wait), the blocked share for a finite station, or "queue grows without bound"; and any extra keys you wrote.
  • The results table lists, per station: Station, Model, c, K (when any station is finite), 1/μ, λ, λ eff (when any station is finite), a (offered load in erlangs), ρ, P(wait), P(block) (when any station is finite), Lq, Wq, L and W.
  • The network line reads, for example, "Offered 12/h · throughput 12/h · L 4.31 in system · W 21.6m end to end · 4 stations", adding "blocked …" when a finite buffer turns arrivals away.
  • The stability line under it reads "Stable — every station holds ρ below 1…", or explains why waiting times are left blank.
  • The verdict is one sentence, coloured green, amber or red.
VerdictMeaning
"Bottleneck: Triage at ρ = 80% on 2 servers — already inside the 85% target; the network is balanced." (green)Every station is under target
"Bottleneck: Assessment at ρ = 91.7% on 3 servers — 4 servers (1 more) would bring it under the 85% target." (amber, or red from 95%)The busiest station needs more servers to meet target
"Unstable — Imaging is offered 1.2 erlangs across 1 server (ρ = 120%), so its queue grows without bound. 2 servers (1 more) would hold ρ at or under 85%."A station is at or above 100% utilisation. Its queue results are shown as "—", not infinity
"Unsolvable — the traffic equations are singular: a routing cycle sends every job back into the network with no exit. Give one station an exit route."A loop with no way out
"No bottleneck is named and no stability verdict is given — part of this network was not read…"A size limit was reached

With no station at all, the figure shows the syntax hint "Describe the network — arrivals 12/h" instead of a verdict. With stations but no arrivals line, every utilisation is 0 and the verdict still names the first station as the bottleneck at "ρ = 0%"; read the No arrivals warning rather than the green sentence.

What it checks

FindingLevelMeaning
Empty networkErrorNothing was recognised as a station, so nothing was solved
Singular routingErrorA routing loop with no exit; no arrival rate exists
Unstable stationErrorA station without a capacity at or above 100% utilisation. Its queue grows without bound, so its Lq, Wq, L and W are shown as "—"
Over targetWarningA station needs more servers to hold the target
Station restatedWarningA station declared twice. The last declaration wins
Service unstatedWarningA declared station with no usable service time, solved as if it took no time
Station unreachedWarningA declared station no traffic reaches
Implicit stationWarningA station named only by a route or arrivals line, given one server and no service time
No arrivalsWarningNo outside stream, so every utilisation is 0
Ambiguous nameWarningA shortened name that matches two stations. The engine refuses to choose and treats it as a station of its own; write the name in full
Routing rescaledWarningProbabilities leaving one station summed past 1 and were scaled down
cv ignoredWarningcv on a finite-capacity station, which is solved exactly as M/M/c/K and assumes exponential service
Line not readGapA line matched no statement, or an arrivals line stated no readable rate
Size limit reachedGapPart of the network was not read. No bottleneck is named
Value coercedGapA value was clamped, rounded or refused, for example servers: 9999 (read as 512), target 150%, a station name over 44 characters, or a refused key
Unitless valueGapA duration or rate was written with no unit and read as seconds or per hour
Assumed targetGapNo target line, so "inside the target" means the default 85%
Downstream of unstableGapA station fed by a saturated one; its figures assume a flow that cannot happen
Fixed point unconvergedGapWith finite buffers in a feedback loop, blocking and throughput did not settle, so the numbers are not a solution
Arrivals blockedInfoA finite buffer is turning arrivals away. Stated because a finite buffer always reads as stable

Templates: Mass Vaccination Centre, Container Terminal Night Shift, Fleet Telemetry Ingest, Emergency Department, Contact Centre, Airport Security, High-Street Coffee Shop, Warehouse Picking, Checkout API Call Chain, Bank Branch Counter, Car Service Centre, Passport Office Counter and CI Build Farm.

Spaghetti diagram

A lean motion study in which the walking is measured.

title "Nurse motion study — ward B, night shift"
scale 1m = 20px
room "Ward B" 24m x 14m
zone "Clean store" at 1,1 size 4x3
station Desk at 12,7
station Bed1 at 3,6
station Bed2 at 5,11
station "Meds room" at 20,3
path "Nurse A" : Desk -> Bed1 -> "Meds room" -> Bed1 -> Desk
path "Nurse B" colour: amber : Desk -> Bed2 -> "Meds room" -> Desk

scenario "After relayout"
station "Meds room" at 11,4

Statements

StatementAlso acceptedWhat it does
room "Name" 24 x 14floor, plan, site; room "X" at 2,2 size 20x10 moves its cornerThe floor rectangle in real units, origin top-left. Without it, the floor is derived from the stations and zones
station NAME at X,Ypoint, node, location, loc, stop, machine, marker; at is optional and the coordinates may be separated by a comma or a space (station Sink 0 4); a bare Pass at 3,6 worksA place people walk to. Restating a station moves it
zone "Name" at X,Y size WxHarea, regionA shaded box for context. Never counted in travel
path "Actor" : A -> B -> Croute, actor, trip, walk, operator, person; arrows ->, →, => or commas; a bare Desk -> Bed1 -> Desk is an unnamed pathOne person's round. A leg may end at a literal point written (12,4)
colour: blue before the final coloncolor:, or a hex value such as #2563ebPins the actor's colour
scenario "After relayout"state, layout, caseStarts the second scenario
scale 1m = 20pxscale 20px per m, scale 20Drawing scale and unit name. Affects only the drawing
unit ftunits ftSets the unit name alone (letters only, up to six). Default m
title "…"title: …Title. The first one wins

Named colours are blue, red, green, amber, orange, yellow, purple, violet, indigo, teal, cyan, pink, magenta, lime, brown, grey, gray, slate and black. Otherwise colours are assigned in declaration order.

A scenario line written before anything else simply names the first layout (for example scenario "Current layout"); otherwise it is called "Before", and an unnamed second scenario is called "After". The second scenario inherits the first scenario's stations, zones and, if it declares none of its own, its paths, so you restate only what moved. A third scenario line does not get a panel of its own: its content joins the second, and the figure says so. The renderer shrinks the scale to fit, so a 200-metre warehouse and a 6-metre kitchen both come out legible.

What it computes

MetricMeaning
Travel per actor and in totalSum of straight-line leg lengths, in your units
LegsTraversals. A retraced leg counts twice
Longest legThe single longest walk between two points
Most-travelled legThe station pair with the most traversals: the link a relayout should shorten first
Visits per stationArrivals and departures. Each station marker carries its count
CrossingsPairs of legs that properly cross. Legs that meet at a shared station, or retrace each other, do not count. Each crossing is ringed
SavingWith a second scenario: distance and crossings saved, absolute and as a percentage of the first

What it checks

FindingLevelMeaning
Station inventedErrorA path names a station no station line placed. It is drawn on a ring inside the floor with a dashed outline, and its distances are not measurements
Station name looks like a keywordErrorFor example statoin Meds at 20,3, which creates a station called "statoin Meds"
Saving from invented positionErrorA before-and-after saving computed with an invented station on either side
Line not readErrorA line matched no statement
No pathWarningStations but nobody walks between them
Plan truncatedGapA size limit was reached
Study resultInfoCrossings, the busiest station and the saving, stated as results

Templates: Nurse Motion Study (Acute Ward), Warehouse Pick Round, Restaurant Kitchen Line, Machine Shop Cell Rebuild, Supermarket Shopper Trip, Office Coffee and Print Runs, Aircraft Turnaround (Stand 14), Hotel Housekeeping Round, Pathology Sample Handling and Construction Site Logistics.

Swimlane process

A cross-functional process diagram with one lane per role or team.

title "Bug triage"
lane "Customer"
lane "Support"
lane "Engineering"

node A "Open ticket"   in Customer   as stadium
node B "Triage"        in Support    as diamond
node C "Fix"           in Engineering
node D "Verify"        in Support
node E "Confirm"       in Customer   as stadium

A -> B
B -> C : "bug"
B -> A : "need info"
C -> D
D -> E
StatementWhat it does
title …Title. If written twice, the last one is drawn
lane "Name"Declares a lane. Lanes are drawn top to bottom in the order declared. With no lane line at all, lanes are taken from the steps in the order they first appear, and every step is reported as being in an undeclared lane
node ID "Label" in LANEA step. The id is one word; the label is one word or quoted
… as rect, as stadium, as diamond, as circleThe step's shape. Default rect
A -> B or A --> BA flow between two steps
A -> B : "label"A labelled flow, such as a decision branch

Columns are assigned automatically by longest path, so each handoff moves visibly to the right. Rework loops (an arrow back to an earlier step) are recognised first and drawn as loop-backs, so they never reverse the layout. Two steps in the same lane at the same stage are stacked in one cell. A step placed in a lane that was never declared gets a lane of its own rather than being merged into the first.

Step boxes and lane headings are measured and wrapped to fit. Up to three error and warning findings are printed on the figure (then "…and N more"), with notes for anything the renderer could not draw: labels shortened with an ellipsis (named by id), steps in undeclared lanes ("drawn in a lane of their own, not merged into the first"), and arrows that name an undeclared step ("not drawn"). A shortened label is also listed as an Info finding with its full wording; every check uses the full text. A line longer than 2,000 characters is not read. With nothing to draw, the figure shows "Add a lane and some nodes — lane "Customer", node A "Open" in Customer".

FindingLevelMeaning
Decision with one way outErrorA diamond with fewer than two outgoing flows
Arrow names an undeclared stepWarningThe arrow cannot be drawn
Lane undeclaredWarningA step names a lane with no lane line
Node redeclaredWarningThe first declaration is drawn; the second is ignored
Decision unlabelledWarningA diamond with an unlabelled branch
Decision duplicate labelWarningTwo branches with the same label
No exitWarningNo step without an outgoing flow, so the process never finishes
Unreachable stepWarningA step, other than the first one declared, that nothing leads to
Lane emptyWarningA declared lane with nothing in it
Line not readGapA line matched no statement. The finding explains the expected form
Empty processGapNo step declared

Templates (26) include Bug triage, Procurement, Hiring loop, Content publishing, Loan approval, Incident response, Employee onboarding, Refund request, Supplier onboarding, Enterprise sales cycle, Sepsis Six Pathway, Goods Receipt Price Dispute, Planning Objection Handling, Pharmacy Dispensing Standard Work and Emergency change (ECAB approval and back-out). For a process to the BPMN 2.0 standard with linting and token simulation, use the BPMN studio.

Kanban board

A board of columns and cards with WIP limits.

title "Sprint 47"
column "To do"
  card "Design login screen"   assignee "Eva"   priority high
  card "Wire up SSO"           assignee "Marco" priority medium tags "auth,sso"
column "In progress" wip 2
  card "Build API"             assignee "Sam"   priority urgent
column "Done"
  card "Spec & RFC"            assignee "Eva"
StatementWhat it does
title "…"Title. If written twice, the last is drawn and the earlier one is reported
column "Name"Opens a column. Quote the name when it contains a space
column "Name" wip 3A column with a WIP limit. The limit is a whole number
card "Title"A card in the column above it
… assignee "Eva"Shown as a round chip with the first two letters of the name ("EV"), followed by the name. Quote names with spaces
… priority low, medium, high or urgentA coloured edge stripe: green, blue, amber or red. Any other word is no priority
… tags "a,b"Comma-separated tags. Quote the list

Each column header shows its card count, and its WIP limit when one is declared; the badge turns to the alarm colour when the count exceeds the limit. A card with no priority gets a neutral assignee chip, distinct from priority medium.

Column headers and card titles are measured and wrapped, and every declared tag is drawn as a chip. Lines the engine cannot read are listed in a notice band under the board ("N things in this source are not on the board above:"), up to six at a time, with the form it expected. This matters most for a mistyped column line: the cards under it are drawn in the column above, and the notice says so ("The 2 cards written after it are drawn in "To do", the column declared above it."). A card written before any column line is not on the board, and the notice says that too. With no column at all, the board shows "Add a column — column "To do" / card "Task"".

FindingLevelMeaning
WIP exceededErrorA column holds more cards than its wip limit
Card outside a columnErrorA card line before any column line; it is not on the board
Card title emptyWarningA card with no title text
Title redeclaredWarningTwo title lines; the last is drawn
Line not readGapA line the engine could not read. For a column line, the cards under it are drawn in the column above
Board emptyGapNo column or card was read

Templates (21) include Sprint board, Support queue, Hiring pipeline, Editorial calendar, Product launch, Bug board, DevOps board, Classroom projects, Research lab, Personal weekly board, Hospital Estates Maintenance, Investigations Desk, Clinical Trial Site Start-Up and Planned Substation Outage Board. To measure flow across a board over time, use Flow metrics (CFD).

Service Blueprint

A Lynn-Shostack service blueprint with five lanes and the three standard dividers.

title: Restaurant Order
subtitle: Sit-down dining experience

evidence:   Signage | Menu card | Plated food | Bill | Receipt
customer:   Arrives → Reads menu → Orders → Waits → Eats → Pays → Leaves
frontstage: Greet & seat | Present menu | Take order | Serve food | Bill | Farewell
backstage:  Reserve table | Check stock | Cook order | Plate up | Settle till
support:    POS | Inventory DB | Kitchen workflow | Accounting
KeyLane or role
title: and subtitle:Heading
note:A note. Repeatable
evidence:Physical evidence: what the customer touches or sees
customer:The customer journey. The line of interaction follows it
frontstage:What employees do in view. The line of visibility follows it
backstage:What employees do out of sight. The line of internal interaction follows it
support:Systems and partners behind the lanes above

Every line is key: value, with the colon required (so title: Restaurant Order, not title "…"), and keys are case-insensitive. Steps within a lane are separated by |, → or ->. The lanes are labelled Physical evidence, Customer journey, Frontstage actions, Backstage actions and Support processes. They are always drawn in that order, whatever order you write them in, and a lane you leave out draws as a thin empty track so the column grid stays aligned. When a lane has many steps the figure grows wider rather than squeezing the boxes. Only a # at the start of a line is a comment in this engine.

FindingLevelMeaning
Line not readErrorA line that is not key: value, dropped whole
Unknown keyErrorA key that is not one of the eight above, such as a mistyped fronstage:. The lane it was meant to open draws empty
Lane repeatedErrorThe same lane written twice; the later line replaces the earlier
Lane emptyWarningA lane key with no steps after it
Step clippedWarningStep text too long to fit its box
Journey missingWarningNo customer: lane, so the dividing lines separate nothing
Lane absent, ragged columns, figure widenedInfoA lane left out (drawn as an empty track); lanes with different step counts (steps line up by position in their lane, not by meaning); or a figure drawn wider than requested so every step box stays readable

Templates: Restaurant order, E-commerce checkout, Telehealth visit, Bank account opening, SaaS trial to paid, Customer support ticket, Hotel check-in, Hospital discharge, Airline booking and Developer onboarding.


Quality and improvement

SIPOC

The Six Sigma define-phase scoping diagram, which also checks itself.

title "New patient registration"
scope "Referral received" -> "Confirmation sent to patient"
owner "Access services team"
metric "Referral-to-appointment days" target: 14 actual: 19 unit: days
metric "First-pass referral acceptance" target: 95% actual: 88% better: higher

suppliers: Referring GP practice, Insurer, Patient
inputs:
  - Referral letter
  - Insurance eligibility response
  - Patient demographics
process: Receive referral -> Verify eligibility -> Create record -> Book appointment -> Send confirmation
outputs: Booked appointment, Confirmation letter, Updated record
customers: Patient, Outpatient clinic, Billing office

requirement input "Referral letter": "Complete, legible, dated within 30 days" (CTQ)
ctq output "Booked appointment": "Within 14 days of referral receipt"

Statements

StatementAlso acceptedWhat it does
suppliers:s:, supplier:, source:, sources:, vendor:, vendors:Opens the Suppliers column
inputs:i:, input:Opens the Inputs column
process:p:, processes:, process step:, process steps:, step:, steps:The process steps
outputs:o:, output:Opens the Outputs column
customers:c:, customer:, client:, clients:Opens the Customers column
title "…"title: …The title. The first one wins
scope "A" -> "B"→ or => for the arrow; a prose sentence such as scope "From referral received to first appointment booked" (to, through, until or thru)The process boundaries. Any other text is shown as written, with no boundary check. The first one wins
owner "…"process ownerThe process owner, shown as a tile. The first one wins
metric "Name" target: … actual: …metrics; goal: or spec: for target; current:, baseline: or today: for actual; unit: or units:; better: or direction: with lower or higher (also less/more, min/max); the phrases higher is better and lower is better; a bare value after the name is the targetA header metric tile with its variance. Up to five metrics
requirement input "Item": "text"req, require; columns input, output, supplier, customerA requirement chip under an item
ctq output "Item": "text"A trailing (CTQ) in the textA requirement flagged critical to quality

Items on a column line are comma-separated; quote an item to keep a comma inside it. A - bulleted line beneath a column adds exactly one item, verbatim. A column opened twice accumulates. Process steps split on ->, →, | or ; when any is present, and on commas otherwise; leading numbering such as 1. or 2) is stripped because the engine numbers the steps itself. Requirements may be written before the column they refer to, and items are matched loosely (case, plurals and partial phrases). better: defaults to lower, because define-phase metrics are mostly times, backlogs and defect counts; write better: higher for yields and acceptance rates.

What it computes

The notes strip reports item counts per column and the number of steps; requirement gaps (each input and output with no stated requirement, named); requirement coverage; the scope check (whether the declared start matches step 1 and the declared end the last step, matched loosely so "Receive referral" and "Referral received" agree); and each metric's variance against target in the declared direction. The figure shows a header strip (title, scope, owner and metric tiles), five aligned columns, the process as a numbered chevron spine (wrapping at five steps a row) and requirement chips under their items.

What it checks

FindingLevelMeaning
Column misfiledErrorA word: line under an open column whose word names no column, so the whole line became items
Line droppedErrorA line before any column opened
Orphan requirementErrorA requirement whose item was not found
Metric unparsedErrorA metric line that could not be read
Requirement unparsedErrorA requirement or ctq line that could not be read
Metric valuelessWarningA metric with neither target nor actual
Empty columnWarningA column with no items
TruncationGapA size limit was reached
Counts, input and output requirement gaps, scope declared, scope start and end, metric varianceInfoThe SIPOC's own results. A requirement gap or a scope mismatch is stated, not scored against the figure

Templates: Blood Bank Unit Issue, Narrowbody Aircraft Turnaround, Clinical Coding to Invoice, Inpatient Discharge, Injection Moulding Cell, Sev-1 Incident Response, Accounts Payable Invoice to Pay, Cold Chain Vaccine Despatch, Undergraduate Enrolment, Offshore Turbine Service, Householder Planning Permission, Omnichannel Apparel Returns and Clinical Trial Site Activation.

Control chart (SPC)

Statistical process control charts whose centre line and limits are computed from your data, never typed in.

title "Fill volume — line 3"
chart xbar-r
unit ml
spec lsl: 495 usl: 505 target: 500
labels: 06:00, 07:00, 08:00
rules: all
subgroup 500.1 499.8 500.4 500.0
subgroup 500.9 501.2 500.7 500.5
subgroup 499.6 500.1 499.9 500.2

Three subgroups are enough to draw, but only just: this example reads "Out of control — 1 of 3 points flagged by rule 1." and carries a rule-window gap, because six of the eight rules need longer runs. A real study wants twenty or more subgroups.

Attribute charts take counts:

chart u
unit "infections per 1,000 catheter-days"
sample n: 1.18 defects: 3
sample n: 1.24 defects: 1
sample n: 0.97 defects: 4

Statements

StatementAlso acceptedWhat it does
chart TYPEtype; see the chart table belowThe chart type. Optional: inferred from the data when absent
subgroup 1 2 3subgroups, group, groups, sg, sub, batch; numbers separated by spaces, commas or semicolonsOne subgroup of measurements
value 12.1values, point, points, x, obs, observation, observationsIndividual readings, one point each
A bare line of numbersData, so pasted columns work
sample n: 1180 defects: 62d:, count:, c:, np:, x:, nonconforming: or events: for the count; size:, units: or area: for n; two bare numbers (n, then count); a bare n: 200 d: 7 lineAttribute data. n may be fractional: for a u chart it is an area of opportunity
spec lsl: … usl: … target: …specs, specification; lower or min, upper or max, nominal; keys in any order; positional numbers (spec 495 505 500); separate lsl: 495, usl: 505 or target: 500 linesSpecification limits. Turns on capability
labels: a, b, clabel:; commas or semicolonsTick labels for the x axis (shortened past 14 characters)
rules: allrule; on, yes, a list such as 1,2,5, or off (none, no)Which Nelson rules to run. Default all eight
unit mlunitsThe unit, up to 40 characters
title "…"Title. Read only before the first data line
ChartYou can writeDataLimits
I-MRi-mr, imr, xmr, i, individual, individuals, mrIndividual readingsSigma from the mean moving range ÷ d2
X̄-Rxbar-r, xbarr, xr, meanrangeSubgroups of 2 to 25X̿ ± A2·R̄; range limits D3·R̄ to D4·R̄
X̄-Sxbar-s, xbars, xs, meansigmaSubgroups of 2 to 25X̿ ± A3·s̄; sigma limits B3·s̄ to B4·s̄
pp, pchart, proportion, fractionDefectives out of np̄ ± 3√(p̄(1−p̄)/nᵢ), stepped per point
npnp, npchart, countDefectives out of nnᵢp̄ ± 3√(nᵢp̄(1−p̄))
cc, cchart, defectsDefect countsc̄ ± 3√c̄
uu, uchart, rateDefects over an area of opportunityū ± 3√(ū/nᵢ), stepped per point

The chart word is read with case, spaces and punctuation ignored, so xbar-r, XbarR and xbar r are the same; xbarrange and xbarsigma are also accepted. An unrecognised chart word is ignored and the type is inferred. With no chart line, counts give a p chart (or c when no n is given), subgroups of one give I-MR, subgroups of nine or more give X̄-S and anything else gives X̄-R. A mismatched pairing corrects itself: chart i-mr with wide subgroups flattens them into individuals rather than refusing to draw. When subgroup sizes vary, the limits step per point. On the attribute charts (p, np, c and u) a lower limit never goes below zero. Variables charts use the published constants table for subgroups of 2 to 25.

What it computes

  • Nelson rules. Each violation is marked on the point that completes the pattern and listed as, for example, "Rule 2 · X̄ at point 14 = 501.20 — 9 points in a row on one side of the centre line". Up to six are listed. Only rule 1 is applied to the range or sigma panel.
  • Verdict. "In control — 24 points, no Nelson-rule violations." or "Out of control — 5 of 24 points flagged by rules 1, 2."
  • Capability. With specification limits: Cp and Cpk from within-subgroup sigma, Pp and Ppk from overall sigma, and expected parts per million out of specification. Capability quoted for an out-of-control process adds "Quoted from an unstable process, so treat it as provisional."
RulePattern
11 point beyond a 3σ limit
29 points in a row on one side of the centre line
36 points in a row steadily increasing or decreasing
414 points in a row alternating up and down
52 of 3 points beyond 2σ on the same side
64 of 5 points beyond 1σ on the same side
715 points in a row within 1σ of the centre line
88 points in a row beyond 1σ, either side

What it checks

FindingLevelMeaning
Reading not readErrorA non-number among the readings, so the chart has one point fewer than you typed
Directive misreadWarningA line whose first word is one letter from a keyword (for example spek lsl: 5) was charted as data
Rules disabled or narrowedGaprules: off, or a subset, so some patterns were not looked for
Rule window unreachableGapToo few points for a rule's pattern to be possible. Rule 7 needs 15 points and rule 4 needs 14, so any chart shorter than 15 points carries this gap with all eight rules on; write rules: 1,5 (or whichever rules the run is long enough for) to say so deliberately
Limits not estimableGapNot enough data to estimate limits
Run truncatedGapMore than 400 points. "In control" is never claimed ("Not assessed — part of this run was not read…"), an out-of-control count is shown with "≥", and capability reads "Cp and Cpk are not stated — part of this run was not read…"

The chart needs at least two subgroups before limits can be estimated. Templates: I-MR (Tablet Press Weight, Stroke Door-to-Needle Time, API p95 Latency, Reactor Peak Exotherm), X̄-R (Bottle Fill Volume, API Assay Concentration, Paint Film Thickness), X̄-S (Moulded Boss Diameter), p (Call Abandon Rate), np (Invoice Error Count), c (Reflow Solder Defects, Body-in-White Weld Defects) and u (Central-Line Infections).

Pareto chart

The 80/20 chart with its headline sentence derived from the data.

title "Customer complaints — H1 2027 vs H2 2026"
unit complaints
period "H1 2027"
compare "H2 2026"
threshold 80%
other-below 2%
max-bars 12
note "Excludes wholesale accounts"

"Late delivery"        412   351
"Damaged packaging"    227   254
"Wrong item shipped"   141   132
"Billing error"         96    88
Unhelpful agent         64    71
DirectiveAlso acceptedWhat it does
title, noteFree text, quoted or bare, up to 140 characters. The first title wins; a later note replaces an earlier one
unitunitsWhat one count is, such as "complaints", "minutes" or "GBP thousands"
periodseries, currentName of the charted series
comparevs, versus, prior, baselineName of the comparison series
threshold 80%cut, vital few, vital-few, vitalThe vital-few cut. Default 80%, clamped to 1–100
other-below 2%fold-below, tail-below, other, foldFold categories under this share of the total into Other. Clamped to 0–50%
max-bars 12max-categories, top, barsFold everything past this many bars into Other. Default 15, from 2 to 30

A data line is a label followed by one or two numbers: the charted period, then optionally the comparison period. A line that opens with a quoted label is always data, so quote a label when it would collide with a directive ("Note failures", "Top cover cracked") or ends in digits. Separators are flexible: Late delivery: 412, Late delivery = 412, Late delivery | 412 351 and Late delivery, 412, 351 all work, and a leading - or * bullet is stripped. Repeated labels are added together, so a tally typed off a check sheet works. Numbers accept 1,234 and 1_234; write the two periods separated by a space so 412 210 is never read as 412,210. A trailing % on a value is ignored. Zero, negative and unreadable values are dropped and reported. A line longer than 2,000 characters is not read, and the tally is then treated as incomplete.

What it computes: each category's share; the running cumulative percentage; the vital few (the leading categories up to and including the one whose bar crosses the threshold); the share they carry; and the Pareto ratio sentence, for example "3 of 11 categories (27%) account for 81.2% of 1,040 complaints". With a comparison period it draws ghost bars and a dashed curve accumulated in the current period's order, and lists the categories that entered or left the vital few. Other is always drawn last and never counted among the vital few. A single category is never folded on its own. The count axis is scaled to the tallest bar so every bar stays readable, while the cumulative curve keeps its own 0–100% axis.

What it checks: a row that could not be read, a value that is not a count, a comparison column that cannot be used (all Error); a zero value and rows discarded past a limit (Gap); labels merged because they repeat, and a directive misread as a data row (Warning). If a size limit is reached, no ratio sentence is written.

Templates: Rail Delay Minutes by Cause, Heat Pump Warranty Claims, Drug Round Interruptions, 30-Day Hospital Readmissions, Injection Moulding Defects, Mobile Crash Signatures, Card Chargeback Reasons, Parcel Network Late Deliveries, First-Year Student Withdrawals, Wind Farm Unplanned Downtime, Council Service Complaints, Retail Stock Loss, Clinical Trial Data Queries and Customer Revenue Concentration.

Fishbone (Ishikawa)

Root-cause diagrams with the problem at the head and categories alternating above and below the backbone.

title "OTIF review"
problem "Late delivery"
category "People"
  cause "Untrained staff"
  cause "Sick days"
category "Process"
  - Manual handoffs
  - No SLAs
category "Equipment"
  Forklift downtime
StatementWhat it does
title "…"Title
problem "…"The effect, in the head box. Wrapped to up to four lines
category "…"Opens a rib
cause "…", - … or • …A cause on the current rib
Any other line under a ribTaken as a cause, verbatim

If no category line is written, four ribs are supplied: People, Process, Equipment and Materials. If no problem line is written, the head reads "Problem". Any other line written before the first category is not on the figure and is reported. The title and problem lines may come anywhere; if either is written twice, the last one is drawn. The canvas widens (by up to 800 px) to hold long causes; a cause or problem too long even for that is shortened with an ellipsis and written out in full in the notice band under the figure, which lists up to five at a time.

FindingLevel
Categories unstated (the four default ribs were supplied)Error
Problem unstatedError
Cause before any category (not on the figure)Error
Category with no causes; category name repeated; cause repeated in a category; problem or title restated; empty cause, problem or category nameWarning
The same cause under two categoriesInfo

Templates include 6 Ms late delivery, Production bug, Low signup conversion, Manufacturing defect rate, Customer churn, Site outage, Slow hiring funnel, Pharmaceutical Batch Deviation, On-Time In-Full Miss, Day-of-Surgery Cancellations, Short-Notice Train Cancellations and Fraud Model Precision Drop. A fishbone pairs naturally with a Pareto chart of how often each cause occurs.

Design structure matrix

Dependency matrices with partitioning, for process sequencing, component coupling, team interfaces or design parameters.

title "Vehicle programme dependencies"
mode process
convention ir-fad
elements: Concept, Styling, Packaging, Body, Chassis, Powertrain, Testing
Styling    <- Concept
Packaging  <- Concept, Styling
Body       <- Packaging, Styling(2)
Chassis    <- Packaging
Powertrain <- Concept, Packaging
Testing    <- Body, Chassis, Powertrain
Styling    <- Testing
StatementWhat it does
A <- B, CA takes input from B and C. ← and <-- also work. Both sides take a comma list, so A, B <- C works too
A -> B, CA feeds B and C. → and --> also work
A depends on BThe same as A <- B
Name(2) or Name:2Dependency strength from 1 to 9 (default 1). Shades the mark, and is shown as a digit when the cell is big enough
elements: …Fixes the as-declared order. Also activities:, components:, teams:, parameters:, tasks:, nodes:. Optional and repeatable
A line with no arrowDeclares one element, so a long header can be written one name per line
mode processprocess, component, team or parameter (plurals and shortened forms also work). Default process
convention ir-fadInputs in rows, feedback above the diagonal (the default, and what any other word means), or ic-fbd (also ic, icfbd, fbd, col, cols, column, columns, inputs-in-columns), the transpose. The figure prints which is in force
legend offHides the legend (no, none, false, hide, hidden and 0 also work)
title "…"Title. Read only before any other content

Names are matched without regard to case, so "Body-in-white" and "body-in-white" merge, and the first spelling is the one drawn. A name used in a dependency but never declared is appended in order of first mention. Self-dependencies are dropped. Because any line without an arrow declares an element, a mistyped keyword line such as elemnts: Body, Chassis becomes one element with that whole text as its name; the check below catches it. The engine computes the cycles (groups that depend on each other), a partitioned order that pushes as many dependencies as possible below the diagonal, the iteration blocks that must be worked together, and the count of feedback marks before and after, for example "23 feedback marks reduced to 6 across 2 iteration blocks". The figure shows the declared and partitioned matrices side by side, with iteration blocks boxed and fan-in and fan-out counts on the right. It checks for a line whose first word is one letter away from a declaration keyword, such as elemnts: … or mod process, and so was not read as the declaration you meant (Warning); self-dependencies, which are dropped (Warning); and a size limit reached (Gap), in which case no sequencing verdict is given.

Templates: EV Vehicle Programme, Checkout Service Coupling, Hospital EHR Go-Live, Payments Team Topology, Goods-to-Person Retrofit, MSc Programme Validation, Offshore Wind Farm Delivery, Benefit Claim Service Redesign, Retail Recommender Platform, Pre-Training Parameter Coupling, Aircraft Cabin Retrofit, Payments Monolith Decomposition, Marketing Authorisation Dossier and an application landscape interface matrix.


Risk, safety and reliability

Fault tree (FTA)

Quantitative fault-tree analysis in IEC 61025 notation, computed exactly.

title "Loss of reactor cooling"
mission 8760h

top "Reactor cooling lost" = AND(pump_fail, backup_fail)
gate pump_fail "Main pump train fails" = OR(motor, power, control)
gate backup_fail "Backup train fails"  = KOFN(2, dg1, dg2, dg3)
gate control "Control loop fails"      = INHIBIT(ctl_fault, high_temp)

event motor "Pump motor failure"   p=0.02
event power "Bus power loss"       rate=1.2e-6
event ctl_fault "Controller fault" mtbf=45000h
condition high_temp "Coolant above 320 C" p=0.15
undeveloped dg1 "Diesel generator 1" p=0.03
undeveloped dg2 "Diesel generator 2" p=0.03
undeveloped dg3 "Diesel generator 3" p=0.03
house maint "Train A out for maintenance" off

Statements

StatementSymbolWhat it does
top [id] ["Label"] = EXPRRectangleThe root. top event also works, and : may replace =. The id defaults to top. top = pump_fail makes an existing gate or event the root. With no top line, the gate nothing else references becomes the root
gate id ["Label"] = EXPRRectangle with its gate symbolAn intermediate event. intermediate and int are aliases, and id = EXPR works without the keyword
event id ["Label"] attrsCircleA basic event. basic and be are aliases
undeveloped id …DiamondAn event not developed further. undev is an alias
house id … on or offHouseA boundary condition, probability 1 or 0. true/false, yes/no and enabled/disabled also work
condition id …OvalA conditioning event for INHIBIT. cond is an alias
mission 8760hMission time, used to turn rates into probabilities. mission time, exposure, exposure time, time and t also work, and the line may come anywhere. Default one year (8760 h), shown as "(default)"
title "…"Title. Read only before the first gate or event
GateAlso writtenMeaning
AND(a, b)ALL(…), a & b, a * b, a · bAll inputs must occur
OR(a, b)ANY(…), a + b, or a pipe character between the inputsAny input suffices
KOFN(2, a, b, c)VOTE, ATLEAST, MOFN, shorthand 2OF3(a, b, c), 2OO3(…) or 2/3(…)At least k of n inputs. Drawn as an OR shield labelled k/n. A k above n is cut to n
INHIBIT(x, cond)INHIBIT(x, condition: cond)x occurs while the condition holds. Drawn as a hexagon with the oval beside it

The keyword form also works without parentheses: OR a, b, c. A gate keeps its first 12 distinct inputs; the rest are counted and reported, and the tree is then treated as truncated. An unknown operator is computed and drawn as OR with a Warning, so the branch keeps drawing. XOR, NOT, NAND and NOR are also computed as OR, and are reported as an Error: they make the tree non-coherent, and the picture would then be defensible while the arithmetic under it describes a different tree.

Event attributeAliasesConverted to a probability by
pprob, probability, q, unavailability, or a bare number; pct or percent for a percentageUsed as written. A value outside 0 to 1 is clamped and reported
ratelambda, λ, freq, frequency1 − e^(−λt) over the mission time, λ per hour. A unit after the number converts it, so rate=1.2e-6 /y is per year
mtbfmttfλ = 1 ÷ MTBF. A bare MTBF is in hours; 45000h, 5 y and similar also work
fitλ = FIT × 10⁻⁹ per hour

Attributes may be written key=value or key: value, in any order.

What it computes

Tile or panelMeaning
Top event probability (exact)Computed exactly with a binary decision diagram, which stays correct when one basic event feeds several branches. The rare-event approximation is printed beside it so you can see how far that shortcut is off
Top event probability (bound)Shown instead when the tree is too large for the exact method: a minimal-cut-set upper bound, labelled as such
Minimal cut setsThe count, with "+" when enumeration stopped at 2,000. The panel lists them by order (size), then probability, up to ten
Smallest cut set order1 means a single component can cause the top event
Single points of failureOrder-one cut sets, highlighted on the tree. Reads "none" only when there are none
Mission timeAs declared, or "(default)"
Repeated basic eventsEvents that feed more than one branch, when there are any
Importance tableBirnbaum (where design effort pays), Fussell–Vesely (share of current risk through each component) and criticality. Up to eight rows

Each node's probability is printed beneath it. A gate used in two places is drawn once and referenced elsewhere by a transfer triangle. The panel's first line reads "Exact top-event probability … · rare-event sum ΣP(cut set) …", followed by how far the usual approximation overstates this tree. When a size limit cut part of the tree (including a gate with more than 12 inputs), the panel opens with "This tree was truncated — no top-event probability is stated.", the top tile reads "Top event probability (withheld)" with "—", and the cut-set and single-point tiles show "≥" and "(partial)".

When the tree cannot be analysed. In four cases nothing is computed, and the figure is replaced by an error card with the title, the reason and "Fix the structure and the tree redraws — nothing else was lost."

Error cardCause
"No top event — write top "Something fails" = AND(a, b)"The root does not resolve to any gate or event the tree declares
"Cyclic gate reference: a then b — a fault tree must be acyclic."A gate reaches itself through its inputs
"70 basic events — exact analysis is capped at 64."More than 64 distinct basic events are reachable from the top
"The tree has no basic events to compute with."Every branch ends at a gate

What it checks

FindingLevelMeaning
Cycle, no top event, top unreadableErrorThe tree has no usable shape
Gate unreadableErrorA gate's inputs could not be read, so the gate is dropped. If another gate refers to it, its id is drawn as an undeveloped diamond at p = 0
Non-coherent gateErrorXOR, NOT, NAND or NOR, computed as OR
Unknown operatorWarningAn operator the engine does not know, computed as OR
Undeclared eventWarningA gate names an id nobody declared; it is carried at p = 0
Event with no probabilityWarningA declared event with no p, rate, mtbf or fit; carried at p = 0
Value out of rangeWarningA probability outside 0 to 1, clamped
Gate restatedWarningA gate or event declared twice; the last wins
Contested topWarningNo top line and several unreferenced gates, so the root was picked from among them
Assumed topInfoNo top line; the one unreferenced gate became the root
Assumed missionGapRates were converted over the default 8760 h
Gate input unread, line not read, size limit reachedGapPart of the document never reached the arithmetic
Too many basic events, no basic eventsGapThe two error cards above: the tree was not analysed
Inexact evaluationGapThe exact method ran out of room; the top figure is a labelled upper bound and the importance measures are approximate
Cut sets truncatedGapEnumeration stopped at 2,000 cut sets
Single point of failureInfoA component that takes the top event on its own. A fact about the system, not a mistake in the document

Templates: Metro Signalling Loss, Vaccine Cold Chain Excursion, Offshore Turbine Unavailability, Reactor Decay Heat Removal, Triple Hydraulic Loss, Data Centre Power to IT Load, Piped Medical Oxygen, Total Loss of Vehicle Braking, Blowout Preventer on Demand, Wrong-Side Signalling Failure, AV Pedestrian Detection, Regional Cloud API Outage and Batch Reactor Overpressure.

Bowtie risk

Threats on the left, the top event at the knot, consequences on the right, and preventive and recovery barriers on every path, with residual risk computed.

title "Loss of containment — LPG storage"
hazard "LPG stored under pressure"
top "Loss of containment"
unit "/yr"

threat "Corrosion of vessel wall" likelihood: 0.1 {
  barrier "Inspection programme" effectiveness: 0.8 type: detection
  barrier "Cathodic protection" effectiveness: 0.6
  escalation "Inspection deferred for turnaround" {
    control "Deferral requires VP sign-off"
  }
}

consequence "Vapour cloud explosion" severity: 5 {
  barrier "Gas detection + ESD" pfd: 0.15
  barrier "Emergency response" 50%
}

Statements

StatementAlso acceptedValue
title, hazard, top, unithaz for hazard; top event or event for top; per for unitThe header. Read only before the first threat or consequence, so a threat called "Top-up line rupture" is never mistaken for one
threat NAME likelihood: 0.1cause, source; value keys l, p, prob, probability, freq, frequency, rateA frequency (events per period), so residual frequencies add at the knot
consequence NAME severity: 5outcome, impact; value keys sev, s, loss, magnitudeSeverity on any scale you use; risk carries the same units
barrier NAME effectiveness: 0.8safeguard, defence, defense; value keys eff, e, reliability, rel, works, success; pfd: (also failure, failurerate, fail, pf) is inverted for you, so pfd: 0.1 is the same barrier as effectiveness: 0.9Probability the barrier works. type: prevention, detection, control, mitigation or recovery is a caption only
escalation NAMEescalation factor, ef, degradationHangs under the barrier above it: what stops the barrier working
control NAMEdegradation controlA degradation control under the escalation above it. At path level, with no escalation open, it is read as a barrier

Braces are optional: barrier attaches to the latest threat or consequence, escalation to the latest barrier and control to the latest escalation. ; and new lines both end a statement. A bare trailing number such as barrier "Deluge" 60% is the statement's natural quantity, but only when the line has no key: value pairs. Values accept 0.8, 80% or 80.

What it computes

ResultHow
Residual threat frequencyLikelihood × product of (1 − effectiveness) over the threat's barriers
Top eventSum of residual threat frequencies; the tile also shows the inherent frequency
Consequence frequencyTop-event frequency through that consequence's recovery barriers
Consequence riskConsequence frequency × severity
Residual riskSum of consequence risks; the tile also shows the inherent risk with every barrier removed
Risk reduction1 − residual ÷ inherent; the tile also shows the threat-side effect
BarriersCount, with threats and consequences
Dominant threatThe threat carrying the largest share of the top event
Barrier criticalityResidual risk recomputed with that one barrier deleted, minus the current residual risk. Up to six are ranked

Line weight shows each path's share of the risk, and barriers are coloured by effectiveness.

Defaults and caps. A threat with no likelihood is assumed 0.1, a consequence with no severity 3, and a barrier with no effectiveness 0.5. Each assumption is listed. Effectiveness is capped at 0.99, because a barrier that cannot fail does not exist.

FindingLevelMeaning
Single barrierWarningA path defended by fewer than two barriers
Uncontrolled escalationWarningAn escalation factor with no degradation control
Inert barrierWarningRemoving the barrier changes the residual risk by exactly nothing: a paper barrier, credited zero effectiveness or sitting on a path that carries no risk
Non-conforming valueWarningA value that could not be used as written: unreadable, below zero, or above the 0.99 effectiveness cap
RestatedWarningSomething declared twice, with one of the two discarded
Unterminated quoteWarningA quotation mark that is never closed
Assumed independenceGapThree or more barriers on a path multiplying out to more than a 100-fold reduction. Common-cause failure is not modelled, so treat that reduction as an upper bound
Assumed inputGapA likelihood, severity or effectiveness the engine substituted
Not read, orphaned statement, size limit reachedGapA statement the engine does not know, a statement with nothing to attach to (such as a barrier before any threat), or a part of the document past a limit
Concurrent consequencesInfoSeveral consequences, each credited the full top-event frequency

When any part of the bowtie was not read (a statement the engine does not know, an orphaned statement, a size limit or an unclosed quotation mark), the Top event, Residual risk and Risk reduction tiles show "—" with "(withheld)", and Barriers is marked "(partial)" with "≥" counts. Otherwise the five tiles are Top event (with the inherent frequency beneath), Residual risk (with the inherent risk), Risk reduction (with the threat-side effect), Barriers (with the threat and consequence counts) and Dominant threat (with its share of the top event). A barrier criticality ranking (up to six) and up to seven findings are printed along the bottom. Templates: LPG Storage Loss of Containment, Wrong-Dose Medication on an Acute Ward, Runway Incursion, Dropped Object from a Drilling Derrick, Ransomware Encryption of Production Systems, Listeria in Chilled Ready Meals, Fall from Height on Steel Erection, Unauthorised Trading, Embankment Dam Overtopping, Customer Data Exfiltration from Cloud Storage, Unsafe LLM Response, Signal Passed at Danger, Ransomware on a Hospital Network and Undeclared Allergen in a Ready Meal.

Reliability block diagram

System reliability, MTTF and availability, computed from series, parallel, k-out-of-n and standby arrangements.

title "Redundant power train"
mission 8760h

block grid "Grid supply"   mtbf: 4000h  mttr: 6h
block ups1 "UPS A"         r: 0.98
block ups2 "UPS B"         r: 0.98
block pdu1 "PDU 1"         mtbf: 260000h
block pdu2 "PDU 2"         mtbf: 260000h
block pdu3 "PDU 3"         mtbf: 260000h
block pumpA "Pump A"       rate: 2.5e-5 /h
block pumpB "Pump B"       rate: 2.5e-5 /h

series {
  grid
  parallel { ups1; ups2 }
  kofn 2 of 3 { pdu1; pdu2; pdu3 }
  standby cold { primary: pumpA; spare: pumpB; switch: 0.99 }
}

In this example only the grid states an mttr, so availability is computed with the other seven blocks counted as always available, and the figure reports that as an Availability partial gap. Give every block an mttr for a complete availability figure.

Blocks

block <id> ["Label"] key: value … (component, item and unit also work), with attributes in any order separated by spaces, commas or semicolons. The label falls back to the id. title "…" sets the title and mission 8760h (or mission time) the mission time; only the first of each is used. Durations take s, min, h (the default), d, w, mo or y, so 4000h, 18 months and 2.5 y all work.

KeyAliasesMeaning
rrel, reliabilityMission reliability, stated directly
qunreliability1 − r
mtbfmttfMean time between failures; R = e^(−t/MTBF)
ratelambda, λFailure rate, for example 2.5e-4 /h, 1.2/y or 85 fit
mttrrepairMean time to repair. Turns on availability

Every form is converted to a constant failure rate, which assumes an exponential life (the standard RBD assumption).

Arrangements

ArrangementAlso writtenReliability
series { a; b; c }seq, sequence, chain, and, or bare bracesProduct of the members
parallel { a; b }par, redundant, any, or1 − product of the members' unreliabilities
kofn 2 of 3 { a; b; c }k-of-n, koon, kn, vote, voting, mofn, m-of-n, majority; of, out, oo, from; kofn 2 { … }Exact, even when members differ. The members you list set n; with no k, a majority (more than half) is required
standby cold { primary: a; spare: b; switch: 0.99 }backup, cold-standby, warm-standby, hot-standbySpares used strictly in order. cold spares do not age, warm age at 10% of their rate, hot at the full rate, or set dormancy: 0.25. switch: is the changeover success probability

Separators ;, , and new lines all delimit members. A name referenced but never declared becomes an assumed perfect block, drawn dashed. A file with blocks and no arrangement is treated as one long series.

What it computes

Tile or lineMeaning
System reliabilityAt the mission time (default 8760 h, one year)
Unreliability1 − reliability
System MTTFIntegrated numerically. Shown as "System MTTF (lower bound)" with "≥" when the system is too reliable to decay within the integration horizon
AvailabilitySteady-state, when any block has mttr; otherwise "no mttr given"
ImportanceEach block's Birnbaum importance and its share of system failure, ranked (up to eight rows)
Weakest linkA sentence of the form "Weakest link: Grid supply — R …, Birnbaum …, …% of system failure. Improving this one block moves the system number further than improving any other."
Redundancy checkEach redundant branch is deleted in turn; a branch worth less than 0.1% of system reliability is flagged as redundancy that buys almost nothing

What it checks

FindingLevelMeaning
No quantitiesErrorEvery placed block is carried at R = 1, so the panel's 1.000000 is not a result
Assumed blockErrorThe arrangement names an id no block line declares. It is drawn dashed and counted as a block that never fails
Unstated reliabilityErrorA declared block with no r, q, mtbf or rate, carried at R = 1
Repeated placementErrorOne block placed twice, which computes one physical component as two independent ones
Empty groupErrorA parallel, kofn or standby with no members, which computes as certain failure
Non-conforming valueWarningA value outside its range, corrected: r: 150 is carried as certainty and r: -1 as impossibility
Unplaced blockWarningDeclared with numbers but never placed, so it is in no result
Block redeclaredWarningThe same id declared twice; the first wins
Attribute restatedWarningTwo statements about one block where only one survived, such as r: beside mtbf:
Singleton groupWarningA redundant group with one member, computed as that member alone
k-of-n arityWarningThe k or n written is not the one computed
Idle redundancyWarningA branch worth less than 0.1% of system reliability
Reliability underflowWarningSystem reliability is too small for the arithmetic to hold and reads as 0. Shorten the mission
Unreadable valueGapAn attribute the engine could not use, such as a zero or negative duration or a negative rate. Reported, never treated as a perfect block
Assumed arrangementGapNo arrangement, so every block was chained in series in declaration order
Assumed mission, mission clampedGapNo usable mission, so 8760 h was used; or a mission above the engine's ceiling was cut down
Availability unstated, availability partialGapNo block gives a readable mttr, or only some do; blocks without one count as always available
MTTF lower boundGapThe system is too reliable to decay within the integration horizon
Line not read, size limit reachedGapPart of the document never reached the arithmetic. When a size limit was reached, the four tiles read "(withheld)" with "—"
Empty diagramGapNothing in the source was read as a block
No redundancyInfoNo redundant group anywhere: every block is a single point of failure. A fact about the design
AND groupInfoA kofn with k equal to n, which is a series in disguise
Weakest linkInfoThe block whose improvement moves the system furthest

Templates: Earth Observation Payload Chain, Potable Water Pumping Station, Radiotherapy Treatment Chain, Data-Centre Power Train, Fly-by-Wire Pitch Channel, Subsea Multiphase Boosting Station, GEO Ku-Band Payload, Hospital Medical Oxygen Supply, 25 kV Rail Traction Chain, Offshore Wind Turbine Drivetrain, Dual-Carrier WAN Path, Autonomous Vehicle Perception Chain, Municipal Water Treatment Works, and two availability models for cloud APIs.

Attack tree

Threat modelling with the attacker's cheapest path rolled up the tree.

title "Steal credentials"
goal G "Steal user credentials"
OR   G1 "Phishing"          parent G
AND  G2 "Server compromise" parent G
leaf L1 "Send phishing email"  parent G1  cost 1   skill low    detect medium
leaf L2 "User clicks link"     parent G1  cost 0   skill none   detect low
leaf L3 "Exploit RCE"          parent G2  cost 5   skill high   detect medium
leaf L4 "Dump password DB"     parent G2  cost 2   skill medium detect high
StatementWhat it does
title "…"Title
goal ID "Text"The attacker's goal, at the root. The tree is rooted at the first goal; a second goal is reported and not drawn
AND ID "Text" parent PA step that needs all of its children to succeed. The text is one word or quoted
OR ID "Text" parent PA step that needs any one of its children
leaf ID "Text" parent PAn attacker action. May add cost N, skill none, low, medium or high, and detect low, medium or high

Lines starting with # or // are comments, and keywords are case-insensitive. With no goal, the figure shows "Add a goal — goal G "Steal credentials"". Leaf cost, skill and detect appear as chips. Cost rolls up the tree: an AND adds its children's costs and an OR takes the cheapest, so the chip on the goal is the price of the cheapest way in. When a child has no cost, the chip says how many steps the number leaves out.

FindingLevelMeaning
Cost incompleteErrorA gate's rolled-up cost left out a child with no cost, so the price shown is lower than the attack's
Node unreachableErrorA node whose parent names nothing, or whose chain of parents does not lead to the goal. It and everything beneath it are not on the figure
Line not readErrorA line that is not a statement (including a leaf with no parent clause), a second goal, or an id declared twice. With a repeated id, children attach to the second declaration and the first is drawn with nothing under it
Gate childlessWarningAn AND or OR with no children
No goalGapNo goal line, so there is no tree to draw
Tree resultInfoThe tree's own result, stated

Diagram Intelligence adds the number of attack scenarios, the cheapest attack and defender choke points (steps present in every attack scenario). On a very large tree the scenario enumeration is cut short and Intelligence says the scenarios and choke points are approximate. Templates include Steal user credentials, Cloud account takeover, Data exfiltration, Ransomware, Account Takeover, Data-Centre Break-in, Web App Compromise, IoT Device Hijack, Card-Not-Present Fraud and Water Treatment Dosing Attack. For software threat models, see also Software and architecture engines.


Automation, control and process engineering

Ladder logic (PLC)

IEC 61131-3 ladder diagrams, solved for one scan exactly as a controller runs them.

title "Motor starter"
state: Start_PB, Stop_PB, Overload_OK, Motor_Run, Eye_Blocked

rung "Seal-in"
  branch
    xic Start_PB
    xic Motor_Run
  xic Stop_PB
  xic Overload_OK
  ote Motor_Run

rung "Jam watchdog"
  xic Motor_Run
  xic Eye_Blocked
  ton T_Jam preset: 6 accum: 8 unit: s

rung "Jam alarm"
--| |--T_Jam----( )--Jam_Alarm

This program solves as three rungs over ten tags, all three true in the declared state, with no findings. Note the rung "Jam alarm" line: an instruction line written while a rung is open joins that rung, so without it the one-line rung would be drawn in series at the end of "Jam watchdog". A one-line rung stands on its own only when no rung block is open, for example at the top of the program.

Statements

StatementAlso acceptedWhat it does
title "…"Title. The first wins
state: A, B=0, Cinputs:, input:The tags that are true. A bare tag is true; Tag = 0 is false. Values accept 1/0, on/off, true/false, closed/open, high/low, yes/no and set/clear. Also read as true: t, y, hi, up, made, live, energised. Also read as false: f, n, lo, down, reset, cleared, deenergised. Any other value, and any non-zero number, reads as true, so write deenergised as one word: de-energised with a hyphen reads as true. The list may continue on following lines until a rung, a title or an instruction line
rungrung "comment", rung 3 "comment"Opens a rung. Following instruction lines join it until the next rung, title or state line
branchparallel, orOpens parallel legs (OR). Each line indented under it is one leg; branches can nest
An instruction line with no rung openBecomes a one-line rung of its own

Instructions

ASCII artKeywordMeaning
--] [--Tag (or the pipe form shown below)xic Tag; also no, noc, contact, examineon, closedNormally open contact: true when Tag is true
--]/[--Tag (or the pipe form shown below)xio Tag; also nc, ncc, notcontact, examineoff, invertedNormally closed contact: true when Tag is false
--( )--Tagote Tag; also coil, out, output, energise, energizeOutput coil, written every scan
--(S)--Tag or --(L)--Tagset Tag; also otl, latch, sealLatch: writes 1, never 0
--(R)--Tag or --(U)--Tagreset Tag; also otu, unlatch, rstUnlatch: writes 0, never 1
ton T preset: 5 accum: 3; also timerOn-delay timer
tof T preset: 5 accum: 3Off-delay timer
tp T preset: 5 accum: 3; also pulsePulse timer
ctu C preset: 500 accum: 412; also counterCount-up counter
ctd C preset: 8 accum: 0Count-down counter

The contacts can also be drawn with pipes, which is how most ladder printouts look:

--| |--Start_PB      # normally open contact, same as: xic Start_PB
--|/|--Jam           # normally closed contact, same as: xio Jam
--( )--Motor         # output coil, same as: ote Motor
--(S)--Alarm         # latch, same as: set Alarm
--(R)--Alarm         # unlatch, same as: reset Alarm

preset: also accepts pre:, pt: and sp:; accum: accepts acc:, et:, cv: and count:. Two bare numbers after the tag are read as preset then accumulated (ton T_Jam 6 8). A trailing s, ms or min is kept as the display unit. The tag always follows its symbol, and may be quoted when it contains spaces. A whole rung fits on one line: --| |--Start_PB----|/|--Jam----( )--Motor.

A timer or counter named T_Jam provides T_Jam.EN (or .CU and .CD), T_Jam.TT and T_Jam.DN, and T_Jam on its own means the done bit. A/B is read as A.B. Tag names are case-insensitive; the first spelling is the one drawn.

How it solves

Tags start from the declared state; everything else is false. Each rung is evaluated left to right: series is AND, parallel legs are OR, a normally closed contact inverts, and an output passes power through, so two coils in series both fire. ote writes every scan; a latch survives its own rung going false; when a set and a reset are both powered in one scan, the last executed wins. Timers and counters resolve their done bits from the declared accumulated value against the preset (IEC rules), and time does not advance during the scan. A coil written on an earlier rung is visible to a later one; to show a seal-in holding, declare the coil in state as it was at the end of the previous scan. Energised rails, contacts and coils are highlighted.

What it flags

FindingLevelMeaning
Duplicate destinationErrorA tag written by more than one output, by an output and a latch, or by two timer or counter blocks. The last rung wins and the earlier one is dead code
Read but never writtenErrorA tag examined by a contact that no output writes and state does not declare: the typo that always reads zero
Rung with no outputWarningLogic solved and thrown away, usually because a coil was deleted
Program truncated, no rungGapA size limit was reached, or no rung was read
Never energisedShown on the stripOutputs no instruction drove true in the declared state. This is a result for that input state, not a defect

When there are none, the strip says so: no duplicate destinations, no unwritten tags, every rung drives an output. Templates: Motor Start/Stop Seal-In, Signalled Junction Sequence, Conveyor Jam Watchdog, Tank Fill on Level Switches, Two-Hand Press Anti-Tie-Down, Roller Door Open/Close Interlock, Packaging Line Fill and Cap, Duplex Pump Duty Alternation, Lift Hall Call and Door Dwell, and Batch Mixer Charge and Soak.

GRAFCET / SFC

IEC 60848 GRAFCET and IEC 61131-3 sequential function charts, checked against the rules every hand-drawn chart breaks.

title "Bottling line — filler cycle"

step 1 "Idle" initial
  action N "Conveyor stopped"
step 2 "Index bottle"
  N "Conveyor forward"
  S "Gate solenoid"
step 3 "Fill"
  N "Fill valve open"
  L 8s "Nitrogen purge"
  D 5s "Alarm horn" if level_low
step 4 "Cap"

transition t1 : "start . bottle_present"
transition t2 : "bottle_at_filler"
transition t3 : "level_high + timeout"
transition t4 : "cap_done"

1 -> t1 -> 2 -> t2 -> 3 -> t3 -> 4
4 -> t4 -> 1

Statements

StatementWhat it does
step 7 "Label"A numbered step. initial (or init) anywhere on the line marks it initial; final (or end) marks a deliberate stopping point. initial step 1 "Idle" also works
action N "Text"An action under the step above. The bare N "Text" and action "Text" (defaults to N) also work
D 5s "Text", L 8s "Text"Delayed and time-limited actions take a time
… if conditionA condition on any action, drawn beside it
transition t3 : "receptivity"A transition's condition. The colon and quotes are optional, and t3 : level_high works
A -> B -> CA link chain. →, => and --> are the same arrow
3 -> t4, t5One step to several transitions: alternative (OR) divergence, single bar
t4, t5 -> 8Alternative convergence, single bar
t2 -> 4, 6One transition to several steps: simultaneous (AND) divergence, double bar
5, 7 -> t8Simultaneous convergence, double bar
QualifierMeaning
NContinuous, while the step is active
SSet (stored)
RReset
DDelayed, with a time
LTime-limited, with a time
PPulse
CConditional

In links, a step is 3, s3 or step 3; a transition is t3, tr3 or transition 3. Nodes referenced but not declared are created, so you can write the spine first. Receptivities pass IEC notation through: . is AND, + is OR and /x is NOT. A transition with no receptivity is drawn =1. A link line may be prefixed with or or alternative, or and, simultaneous or parallel; the engine checks that word against the structure. Links that run back up the chart are routed down the left rail with an arrowhead.

What it checks

FindingLevelMeaning
Alternation breakErrorA step linked straight to a step, or a transition to a transition. Each pair is named and drawn in the warning colour
No initial step, or severalErrorChecked per connected sequence
Unreachable stepErrorNo path from its sequence's initial step
AND unbalancedErrorA simultaneous divergence not closed by a convergence of the same width
Unopened convergenceErrorA simultaneous convergence with no matching divergence
Duplicate stepErrorA step number declared twice. The first declaration is kept
Dangling transitionErrorA transition not connected on both sides
Line not read, no linksErrorA line the engine could not read, or a chart with steps but no links
Dead-end stepWarningNo outgoing transition and not marked final
Unconditional transitionWarningA transition with no receptivity, drawn =1
Keyword mismatchWarningAn or or and prefix that contradicts the chart
Step undeclaredWarningA step that appears only in links; actions written under a mistyped step line attach to the step above
Chart truncatedGapA size limit was reached, so the chart is not called well formed
Chart shapeInfoThe chart's own structure, stated

Templates: CIP Sequence (10 000 L Fermenter), Rotary Bottling Filler, Lift Car Door Interlock, CNC Automatic Tool Change, Batch Reactor Heat-Hold-Cool, Car Park Entry Barrier, Robot Pick-and-Place Cell, Rollover Car Wash Gantry, Signalised T-Junction Stages, Commercial Dishwasher Cycle and Cleanroom Material Airlock.

P&ID (chemical engineering)

Process and instrumentation diagrams placed on a grid.

title "Continuous distillation"
eq tank      T1   "Feed tank"     at (1,1)
eq pump      P1   "Feed pump"     at (3,1)
eq column    COL1 "Distillation"  at (5,1)
eq exchanger E1   "Reboiler"      at (7,3)
eq tank      T2   "Bottoms"       at (5,4)
instrument TI 101 at (6,0.2)
instrument LC 201 at (6,1.8)
instrument PSHH 12-101 at (3,0.2)
line T1 P1 stream "feed"
line P1 COL1 stream "feed (pumped)"
line COL1 T2 stream "bottoms"
line COL1 E1 stream "reboil vapor"

This layout draws with no notices. Put the reboiler at (5,3), directly between the column and the bottoms tank, and the figure reports "The bottoms line is drawn through E1; it does not connect to it."; put a balloon on the column's own coordinates and it reports "Balloon TI 101 is drawn on top of COL1 — both are on the figure, one over the other."

StatementWhat it does
eq KIND ID ["Label"] at (x,y)A piece of equipment. The label is optional; the id is drawn in bold under the symbol with the label beneath it. Coordinates are grid cells and may be decimal or negative
instrument TAG NUMBER at (x,y)An ISA-5.1-style balloon. The tag is a letter followed by up to five letters or digits (FT, TI, LC, PSHH, PALL, LSHH, PDIT); the loop number may carry suffixes and prefixes such as 101A or 12-101
line FROM TO [stream "label"]A process line between two pieces of equipment, with an optional stream label
title …Title
Equipment kindDrawn as
tankRound outline
vesselVessel with domed ends
columnTall column with trays
exchangerShell with a coil
pumpCircle with a discharge triangle
compressorTrapezoid
reactorBox marked R
separatorHorizontal drum
filterBox with dashed media lines
valveBow-tie valve symbol
Any other wordPlain square

Lines starting with # or // are comments. Equipment kinds are matched without regard to case. The notice band under the drawing lists, up to six at a time (then "…and N more."), anything the engine could not draw cleanly.

FindingLevelNotice text or meaning
Line not readError"Line N, "…", is not a declaration this engine reads — nothing on the figure comes from it."
Endpoint unknownError"Line N routes A → B, but B names no equipment — that stream is not drawn."
Content clippedError"This drawing needs Npx of width and was given Mpx — content past the right edge is not on the figure." Bring the far-right coordinates in
Pipe crosses equipmentWarning"The … line is drawn through …; it does not connect to it." A process line that had to be drawn through unrelated equipment
Balloon overlapsWarningAn instrument balloon on top of equipment ("…is drawn on top of…"), over a tag block ("…covers the tag block of…"), over another balloon ("…overlap each other.") or on a line's elbow ("…sits on the elbow of…")
No equipmentGapNothing was declared with eq
ResultInfoThe drawing's own counts, stated

Templates: Water Treatment Plant, Brewhouse Wort Line, Food Waste Anaerobic Digester, Continuous distillation, CSTR with cooling and Shell-and-tube heat exchanger.


The Studio library's Flow systems and Risk & reliability groups also hold engines that are documented in full elsewhere. In Flow systems: Data flow diagram and Event storming (Software and architecture engines); User story map, Business model canvas, Customer journey map, Decision matrix (weighted / Pugh), Gantt & critical path and Roadmap (Business, strategy and planning engines). In Risk & reliability: Decision tree and Risk matrix (Business, strategy and planning engines). Use the Risk matrix for a scored likelihood × impact register and heat map; use a bowtie or fault tree on this page when you need the barriers or the failure logic computed.

Two schedule engines sit closest to this family:

EngineUse it forReference
Gantt & critical pathSchedules computed from durations, all four precedence relationships with lead and lag, a working calendar, resources and deadlines, with critical path, float and conflicts flagged. view network draws the same schedule as a precedence network/docs/engines/gantt
PERT / CPM networkA finish-to-start network with ES, EF, LS, LF and slack in every node and the critical path highlighted. task A "Design" duration 5, task B "Build" duration 10 after A, milestone M1 "Launch" after D, and unit days or unit hours to name the unit (with no unit line, durations are shown without one). In the library it sits under Engineering & physical/docs/engines/pert

Choosing between close cousins

QuestionUseRather than
Where does the time go in an end-to-end process, and which step cannot meet demand?Value stream mapA swimlane, which shows handoffs but computes no times
Is our board's flow getting better or worse over weeks?Flow metrics (CFD)A Kanban board, which is a snapshot
How many servers or staff does each station need?Queueing networkDiagram Intelligence's flow arithmetic, which compares shapes with 16 test arrivals and is not for capacity planning
How far do people walk, and what does a relayout save?Spaghetti diagramA floor plan with hand-drawn lines
What is in and out of scope for an improvement project?SIPOCA process map, which has no requirements
Is this process stable, and is it capable?Control chart (SPC)A run chart in a charting engine, whose limits would be typed by hand
Which few causes deserve attention first?Pareto chartA bar chart, which does not compute the vital few
What might be causing this problem?FishboneA mind map
How likely is a failure and which combinations cause it?Fault treeA bowtie, which reasons in frequencies through barriers
Which barriers matter, and what is left after them?BowtieA fault tree, which has no barriers
How reliable and available is the whole system?Reliability block diagramA fault tree of the same system, which answers the failure question rather than the success one
Does this PLC logic do what I think in this input state?Ladder logicGRAFCET, which describes sequence rather than scan logic
Is this machine sequence well formed?GRAFCET / SFCA state machine or flowchart, which does not check IEC alternation
A process to the BPMN 2.0 standard, with simulationThe BPMN studioA swimlane

Limits at a glance

These limits apply per figure. Past a limit, the engine keeps what it read, says what it did not, and withholds whole-figure verdicts.

EngineLimits
Value stream map60 steps (processes plus waits and inventories), 10 information flows, 6 extra data-box keys per step, 10 rows per data box, labels of 64 characters, 4,000 lines
Flow metrics (CFD)8 stages, 400 data rows, 8 WIP limits, stage and row labels of 48 characters; up to 6 warnings and 5 notes shown
Queueing network14 stations, 160 routes, 32 arrival streams, 512 servers and capacity 512 per station, names of 44 characters, 5,000 lines
Spaghetti diagram200 stations, 60 zones, 24 paths, 240 stops on one path, 600 legs, 2 scenarios, 4,000 lines
SIPOC24 items per column, 40 process steps, 120 requirements (3 per item), 5 metrics, 4,000 lines
Control chart (SPC)400 points, subgroups of up to 25, 256 numbers on one line
Pareto chart200 categories read, 2 to 30 bars drawn (15 by default), lines of 2,000 characters
Design structure matrix64 elements, 3,000 dependencies, 4,000 lines
Fault tree200 gates, 64 distinct basic events reachable from the top (beyond that the tree is not analysed), 12 inputs per gate, 2,000 cut sets; 10 cut sets and 8 importance rows shown; mission time up to about 1,000 years; 4,000 lines
Bowtie12 threats, 12 consequences, 6 barriers per path, 4 escalation factors per barrier, 4 controls per escalation, 4,000 lines
Reliability block diagram120 blocks, 32 members per group, nesting 12 deep, 4,000 lines
Ladder logic40 rungs, 24 elements per rung, 16 per line, 8 legs per branch, branches 5 deep, 40 tags in state, 4,000 lines
GRAFCET / SFC60 steps, 60 transitions, 240 links, 8 actions per step, 4,000 lines
P&IDUp to 6 notices listed at a time
KanbanUp to 6 notices listed at a time
SwimlaneLines of 2,000 characters; up to 3 findings printed on the figure
FishboneThe canvas widens by up to 800 px before a cause is shortened; up to 5 notices listed at a time
Service Blueprint, Attack treeNo engine-specific count limits. Long labels are wrapped or shortened and reported

Every engine on this page also has a source-size budget in the Studio: 60,000 bytes (about 58.6 KB) of source, or 150,000 bytes (about 146.5 KB) for the control chart and the CFD, whose sources grow one row per observation. Past it the figure is not drawn and you see "Source is … — past the … safe-rendering budget for …", with three options: split the work into smaller figures, render it on the server with the render API, or trim the source. See Troubleshooting and FAQ.

Tips

  • Start from a template. Every engine here has a set of real-world templates. Open one, then replace its numbers with yours: the structure is already right.
  • Write the inputs, never the totals. If you find yourself wanting to type a total, a limit, a probability or a verdict, that is the number the engine computes. Type the facts it is computed from.
  • Give units every time. Write 8m, 12/h and 4000h rather than bare numbers. The queueing network reports every unitless value, and in the value stream map a bare number is seconds.
  • Mark the waiting. In a CFD, * on waiting stages is what makes flow efficiency possible. In a value stream map, wait and inventory lines carry the non-value-added time.
  • Use the before-and-after forms. The spaghetti scenario and the Pareto compare column turn one figure into an argument with the difference computed, and the queueing target turns the verdict into a server count you can act on.
  • State the takt. Without takt, or demand with available, a value stream map cannot say which step is over takt.
  • Declare the previous scan. In ladder logic, a seal-in only holds if the coil is in state as it was at the end of the last scan.
  • Mark the deliberate ends. In GRAFCET, mark terminal steps final so the dead-end check does not report them.
  • State what the engine would otherwise assume. A queueing network with no target line, a fault tree with rates but no mission line, any RBD with no mission line, and a control chart shorter than 15 points with all eight rules on each carry a Gap in Document status, because a number was chosen for you. Write target 85%, mission 8760h or rules: 1,5 and the gap clears.
  • Read the notes before you present. A note such as "1 threat likelihood assumed 0.1" on a bowtie, or "Timings assumed" in Diagram Intelligence, is the line a reviewer will ask about.
  • Name a version before a what-if. Open the diagram timeline (Version history…, ⇧⌘H) to name the current version, then change the inputs. See Version history and undo.
  • Keep one figure per engine you try. Picking a different engine replaces the figure's source with that engine's starter, so start a New figure (⌥⌘N) for each comparison and keep both.

Limits and known constraints

  • The Studio computes; it does not animate. These engines draw their results into a static figure. Animated token flow is in Weave and the BPMN studio.
  • The queueing network is a steady-state, open-network model. It treats arrivals as Poisson unless a station states a cva, solves long-run averages, and uses the Allen–Cunneen approximation whenever variability is stated on a multi-server station or on arrivals. A finite-capacity station is always solved as M/M/c/K, ignoring any cv. A station at exactly ρ = 100% counts as unstable. It does not model priorities, schedules that change over the day, or closed networks, and at most 14 stations are solved.
  • Reliability block diagrams assume constant failure rates (an exponential life), so they do not substitute for a Weibull analysis of wear-out. Repair is used only for steady-state availability.
  • Bowtie barriers are treated as independent. Common-cause failure is not modelled, and each consequence is credited the full top-event frequency. Both are reported when they matter.
  • Fault trees must be coherent for cut sets to be meaningful. XOR, NOT, NAND and NOR are accepted but computed as OR and reported as errors. A tree with more than 64 distinct basic events is not analysed at all, and a very tangled tree that exhausts the exact method falls back to a labelled upper bound.
  • Ladder logic solves one scan. Timers and counters do not advance; their state comes from the accum you declare.
  • The CFD's cycle time is approximate, from Little's Law over the window, and assumes a reasonably stable system. The value stream map converts count-only inventories to time only when takt is known.
  • P&ID is a drawing aid, not a process simulator. It has one generic valve symbol (gate, ball, check and control valves are not distinguished), lines are routed automatically between equipment, and you place items by grid coordinates.
  • Swimlane, Kanban, Fishbone, Attack tree, P&ID and Service Blueprint accept comments only on lines of their own (and Service Blueprint only with #).
  • Direct click-to-edit tools are limited here. Click a label on the figure to rename it (Enter saves, Esc cancels); the new text is written straight into your source. When the old label cannot be located in the source safely, the rename is handed to AI instead, and any other change goes through Ask the flowss Studio Agent… in the same popover. Both of those need AI on your plan. Everything else is edited in the code. See Data, timeline, TikZ and the diagram tools.

Troubleshooting

What you seeWhat it meansWhat to do
A syntax hint in place of the figureThe engine found nothing it could drawCompare your lines with the examples on this page, or start from a template. The table below lists each engine's hint
"…is empty because the document was not read to the end."A size limit was reached before anything drawableShorten the document or split it; see Limits at a glance
A tile labelled "(withheld)" or a value shown with "≥"Part of the document was not read, so ratios and verdicts are withheld and sums are floorsFix the lines named in the notes, or reduce the size
A line reported as not read, or "matched no directive"A misspelt keyword or a note written without #Correct the keyword or comment the line out
Flow efficiency "n/a" in a CFDNo stage is marked as waitingAdd * after the waiting stages' names
"Unknown commit stage …" in a CFDcommit names no stageUse the exact stage name from stages:
"Needs at least two subgroups before limits can be estimated."Too little SPC dataAdd more subgroups or readings
"Unstable — … its queue grows without bound."A queueing station is at or above 100% utilisationAdd servers, shorten the service time or reduce arrivals. The verdict names how many servers would meet the target
"Unsolvable — the traffic equations are singular…"A routing loop with no exitRoute some probability from one station in the loop to exit
A queueing verdict of "ρ = 0%" with a No arrivals warningThe network has stations but no arrivals line, so nothing enters itAdd arrivals NAME 12/h (or whatever the real rate is)
A dashed station in a spaghetti diagramA path names a station you never placedAdd a station NAME at X,Y line, or fix the spelling
"Cyclic gate reference: … — a fault tree must be acyclic."A gate refers back to itself through its inputsRemove the circular reference
"… basic events — exact analysis is capped at 64."More than 64 distinct basic events are reachable from the topSplit the tree into sub-trees, or model a sub-system as one undeveloped event with its own probability
"The tree has no basic events to compute with."Every branch ends at a gateAdd event lines for the leaves
"Top event probability (bound)"The exact method ran out of room on a very tangled treeReduce repeated events or tree size, or accept the labelled upper bound
A queueing value reported as coerced with "ρ is COMPUTED…" or "a SQUARED coefficient of variation…"You stated rho, utilisation or scv in a station blockRemove it. State servers and service time, and write cv unsquared
An RBD reading 1.000000 with "no quantities"No placed block states a reliabilityGive each block r, q, mtbf or rate
An attack-tree chip lower than you expectedA child has no cost, so the roll-up leaves it outAdd cost to every leaf; the chip says how many steps it is missing
A bowtie finding "assumed …"A likelihood, severity or effectiveness was missing and a default was usedGive the missing value
A dashed block in an RBDThe arrangement names a block you never declared, assumed perfectDeclare the block with r, mtbf or rate
A Kanban notice that cards "are drawn in" another columnA column line above them could not be readFix the column line; quote names with spaces and use a whole-number wip
A swimlane note that an arrow "names a step this diagram never declares — not drawn"The arrow uses an id with no node lineUse the node's id, not its label
A P&ID notice "…names no equipment — that stream is not drawn."A line endpoint is not an equipment idUse the id from the eq line
A GRAFCET link drawn in the warning colourSteps and transitions do not alternate on that linkInsert the missing transition or step
Ladder "read but never written" for a tag you expected to be trueThe tag is not in state and no output writes itAdd it to state, or fix the spelling
A seal-in rung that does not holdLadder solves one scan; the coil was false at the start of itDeclare the coil in state as it was at the end of the previous scan
A SIPOC "orphan requirement"A requirement names an item no column holdsMatch the item's wording (case and plurals are forgiven) or add the item
A control chart "directive misread"A first word one letter from a keyword, such as spek, was charted as dataCorrect the keyword; the stray number is removed from the run
"Source is … — past the … safe-rendering budget for …"The source is over the Studio's size budget for this engine (60,000 bytes, or 150,000 for SPC and CFD)Split the work across several figures, trim the source, or render it on the server with the render API
A value stream line reported as "matched no directive" although the step is on the mapThe step was written as a bare NAME { … }, or its data box spans several linesStart the line with process and keep the data box on one line
A Document status gap such as "assumed target", "assumed mission" or "rule window unreachable"The engine used a value you did not state, or the run is too short for some Nelson rulesState it: target 85%, mission 8760h, or a rules: list that fits the run
A DSM element named like a keyword, such as "elemnts: Body, Chassis"A mistyped declaration line became one elementCorrect the keyword; the "declaration misread" warning names the line

Empty-figure hints by engine

EngineHint shown when nothing could be drawn
Value stream map"Describe the stream, top to bottom"
Flow metrics (CFD)"Cumulative flow diagram", with the expected row format
Queueing network"Describe the network — arrivals 12/h"
Spaghetti diagram"Place the floor, then walk it"
SIPOC"Scope the process — one column per line"
Control chart (SPC)"Add measurements — subgroup 500.1 499.8 500.4 500.0"
Pareto chart"Add one category per line — "Late delivery" 412", or "Nothing here could be charted, and it is not because the document is empty." when every line failed to read
Design structure matrix"Design structure matrix — declare elements, then their inputs"
Fault tree"Describe the tree — top "Cooling lost" = AND(pump_fail, backup_fail)"
Bowtie"Describe the risk — threats on the left, consequences on the right"
Reliability block diagram"Declare blocks then arrange them — block ups1 "UPS A" r: 0.98"
Ladder logic"Wire a rung between the rails, then say which tags are true"
GRAFCET / SFC"Chart the sequence — steps, transitions, and the links between them"
Swimlane process"Add a lane and some nodes — lane "Customer", node A "Open" in Customer"
Kanban board"Add a column — column "To do" / card "Task""
Attack tree"Add a goal — goal G "Steal credentials""

Fishbone, Service Blueprint and P&ID have no hint: an empty fishbone draws the four default ribs around a "Problem" head, an empty blueprint draws five empty lanes, and an empty P&ID draws an empty grid.

Something unclear or out of date on this page? Tell us from the Support link in any studio — the flowss team reads every report.

© 2026 Voranox Inc. flowss — Flow Systems Studio. All rights reserved.

This documentation, its text and its examples are protected by copyright. Engine and format names are trademarks of their respective owners — see the terms and copyright and licences.